--------[ AIDA64 Extreme ]----------------------------------------------------------------------------------------------

                                                AIDA64 v6.25.5400/ru
                                        4.5.816.8-x64
                                      http://www.aida64.com/
                                              
                                             HOME-
                                             Home
                                   Microsoft Windows 7 Ultimate 6.1.7601.19160 (Win7 RTM)
                                                  2020-06-06
                                                 09:06


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI x64-based PC
                                     Microsoft Windows 7 Ultimate
                                       Service Pack 1
      Internet Explorer                                 11.0.9600.18230
      DirectX                                           DirectX 11.1
                                           HOME-
                                         Home
                                              Home-
       /                                       2020-06-06 / 09:06

     :
                                                   TripleCore AMD Athlon II X3 450, 3200 MHz (16 x 200)
                                          Asus M5A78L-M LX3  (1 PCI, 1 PCI-E x1, 1 PCI-E x16, 2 DDR3 DIMM, Audio, Video, Gigabit LAN)
                                    AMD 760G, AMD K10
                                         8192   (DDR3 SDRAM)
      DIMM1: Kingston 99U5471-050.A00LF                 8  DDR3-1600 DDR3 SDRAM  (11-11-11-28 @ 800 )  (10-10-10-27 @ 761 )  (9-9-9-24 @ 685 )  (8-8-8-22 @ 609 )  (7-7-7-19 @ 533 )  (6-6-6-16 @ 457 )
       BIOS                                          AMI (05/05/16)
                                    Nuvoton Communications Port (COM1)

    :
                                            AMD Radeon R7 240 Series  (2 )
                                            AMD Radeon R7 240 Series  (2 )
                                            AMD Radeon R7 240 Series  (2 )
                                            AMD Radeon R7 240 Series  (2 )
      3D-                                    AMD Radeon R5 420
                                                 LG E1941 (Analog)  [18.5" LCD]  (103TPAE3B104)

    :
                                         ATI Radeon HDMI @ AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller
                                         Realtek ALC887 @ ATI SB750 - High Definition Audio Controller

     :
      IDE-                                    AMD PCI IDE Controller
      IDE-                                    AMD SATA Controller (IDE Mode)
                                      WD5001AALS-00LWTA0 ATA Device  (465 , IDE)
      SMART-                         OK

    :
      C: (NTFS)                                         146.1  (100.2  )
      D: (NTFS)                                         319.3  (181.2  )
                                             465.4  (281.4  )

    :
                                               HID
                                                    HID- 

    :
        IP                                192.168.0.103
        MAC                               60-45-CB-A4-9E-18
                                          Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20)  (192.168.0.103)
                                          TAP-Windows Adapter V9

     :
                                                 Fax
                                                 Microsoft XPS Document Writer
       USB1                                   ATI SB750 - OHCI USB Controller
       USB1                                   ATI SB750 - OHCI USB Controller
       USB1                                   ATI SB750 - OHCI USB Controller
       USB1                                   ATI SB750 - OHCI USB Controller
       USB1                                   ATI SB750 - OHCI USB Controller
       USB2                                   ATI SB750 - EHCI USB 2.0 Controller
       USB2                                   ATI SB750 - EHCI USB 2.0 Controller
      USB-                                    USB2.0 Camera
      USB-                                    USB2.0 Camera
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                     USB 
      USB-                                     USB 
                                                   ()

    DMI:
      DMI  BIOS                                American Megatrends Inc.
      DMI  BIOS                                   1401
      DMI                           System manufacturer
      DMI                                        System Product Name
      DMI                                System Version
      DMI                         System Serial Number
      DMI  UUID                                20998D89-6C2AE711-8AA16045-CBA49E18
      DMI                    ASUSTeK Computer INC.
      DMI                                 M5A78L-M LX3
      DMI                           Rev X.0x
      DMI                    170499767302584
      DMI                             Chassis Manufacture
      DMI                                    Chassis Version
      DMI                             Chassis Serial Number
      DMI Asset-                                Asset-1234567890
      DMI                                       Desktop Case


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 HOME-
      DNS               Home-
      DNS              
      DNS              Home-
     NetBIOS                 HOME-
      DNS               Home-
      DNS              
      DNS              Home-


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           American Megatrends Inc.
                                                  1401
                                             05/05/2016
                                                  2 
       BIOS                                8.15
                                   Floppy Disk, Hard Disk, CD-ROM, ATAPI ZIP, LS-120
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS
                                 DMI, APM, ACPI, ESCD, PnP
                                   ISA, PCI, USB
                                       

     BIOS:
                                                   American Megatrends Inc.
                                     https://ami.com/en/products/bios-uefi-firmware
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates

  [  ]

     :
                                           System manufacturer
                                                 System Product Name
                                                  System Version
                                           System Serial Number
      SKU#                                              To Be Filled By O.E.M.
                                               To Be Filled By O.E.M.
        ID                       20998D89-6C2AE711-8AA16045-CBA49E18
        ID (GUID)                898D9920-2A6C-11E7-8AA1-6045CBA49E18
                                           

  [   ]

      :
                                           ASUSTeK Computer INC.
                                                 M5A78L-M LX3
                                                  Rev X.0x
                                           170499767302584
                                            To Be Filled By O.E.M.

      :
                                                   ASUSTeK Computer Inc.
                                     https://www.asus.com/Motherboards
        BIOS                          https://www.asus.com/support
                                     http://www.aida64.com/goto/?p=drvupdates
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates

  [  ]

     :
                                           Chassis Manufacture
                                                  Chassis Version
                                           Chassis Serial Number
                                            Asset-1234567890
                                                
                                     
                               
                                  
                                   

  [  / AMD Athlon(tm) II X3 450 Processor ]

     :
                                           AMD
                                                  AMD Athlon(tm) II X3 450 Processor
                                           To Be Filled By O.E.M.
                                            To Be Filled By O.E.M.
                                          To Be Filled By O.E.M.
                                          200 
                                     3200 
                                          3200 
                                                     Central Processor
                                       1.4 V
                                                  
                                               Socket AM3
                                              AM3R2
      HTT / CMP Units                                   1 / 3
                                             64-bit

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com/en/products/processors-desktop
                                     http://www.aida64.com/goto/?p=drvupdates

  [ - / L1-Cache ]

     :
                                                     Unified
                                                1 ns
                                                  
                                             Write-Back
                                         2-way Set-Associative
                                       384 
                                      384 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L1-Cache

  [ - / L2-Cache ]

     :
                                                     Unified
                                                1 ns
                                                  
                                             Write-Back
                                         16-way Set-Associative
                                       1536 
                                      1536 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L2-Cache

  [ - / L3-Cache ]

     :
                                                     Unified
                                                1 ns
                                                  
                                             Write-Back
                                       0 
                                      0 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L3-Cache

  [   / System Memory ]

      :
                                               
                                     
                                         
      .                                  16 
                                        2

  [   / DIMM0 ]

      :
      -                                       DIMM
                                                     Synchronous
                                                  8 
      .                                      1600 MT/s
                                             64 
                                            64 
                                              DIMM0
                                                    BANK0
                                           Manufacturer0
                                           SerNum0
                                            AssetTagNum0
                                          PartNum0

  [   / DIMM1 ]

      :
      -                                       DIMM
                                              DIMM1
                                                    BANK1
                                           Manufacturer1
                                           SerNum1
                                            AssetTagNum1
                                          PartNum1

  [   / PCIEX1_1 ]

      :
                                       PCIEX1_1
                                                     PCI-E
                                           Available
                                        32-bit
                                                   
      ID                                                9

  [   / PCIE16X ]

      :
                                       PCIE16X
                                                     PCI-E
                                           
                                        32-bit
                                                   
      ID                                                2

  [   / PCI1 ]

      :
                                       PCI1
                                                     PCI
                                           Available
                                        32-bit
                                                   
      ID                                                12

  [   / Keyboard ]

      :
                                                Keyboard Port
                                   PS/2 KeyBoard
                                    
                                      
                                       PS/2

  [   / PS2Mouse ]

      :
                                                Mouse Port
                                   PS/2 Mouse
                                    
                                      PS2Mouse
                                       PS/2

  [   / USB12 ]

      :
                                                USB
                                   USB12
                                    
                                      USB12
                                       USB

  [   / USB34 ]

      :
                                                USB
                                   USB34
                                    
                                      USB34
                                       USB

  [   / LAN ]

      :
                                                Network Port
                                   LAN
                                    
                                      LAN
                                       RJ-45

  [   / Audio_Line_In ]

      :
                                                Audio Port
                                   Audio_Line_In
                                    
                                      Audio_Line_In
                                       Mini-jack (headphones)

  [   / Audio_Line_Out ]

      :
                                                Audio Port
                                   Audio_Line_Out
                                    
                                      Audio_Line_Out
                                       Mini-jack (headphones)

  [   / Audio_Mic_In ]

      :
                                                Audio Port
                                   Audio_Mic_In
                                    
                                      Audio_Mic_In
                                       Mini-jack (headphones)

  [   / D_SUB ]

      :
                                                Video Port
                                   VGA
                                    
                                      D_SUB
                                       DB-15 pin female

  [   / COM1 ]

      :
                                   COM1
                                    
                                      COM1
                                       9 Pin Dual Inline (pin 10 cut)

  [   / SATA3G_1 ]

      :
                                   SATA3G_1
                                       

  [   / SATA3G_2 ]

      :
                                   SATA3G_2
                                       

  [   / SATA3G_3 ]

      :
                                   SATA3G_3
                                       

  [   / SATA3G_4 ]

      :
                                   SATA3G_4
                                       

  [   / CPU FAN ]

      :
                                   CPU FAN
                                       

  [   / CHA FAN ]

      :
                                   CHA FAN
                                       

  [   / USB56 ]

      :
                                                USB
                                   USB56
                                    USB
                                       

  [   / USB78 ]

      :
                                                USB
                                   USB78
                                    USB
                                       

  [   / PANEL ]

      :
                                   PANEL
                                       

  [   / AAFP ]

      :
                                   AAFP
                                       

  [   / ATI ]

      :
                                                ATI
                                                     Video
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Ethernet
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Sound
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                  

  [  ]

    :
      OEM String                                        6045CBA49E18
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   TripleCore AMD Athlon II X3 450
                                             Rana
                                              BL-C3
      Engineering Sample                                
        CPUID                                      AMD Athlon(tm) II X3 450 Processor
       CPUID                                      00100F53h
      CPU VID                                           1.4000 V
        VID                                 1.1750 V

     :
                                               3214.4 MHz  (: 3200 MHz)
                                             16x
      CPU FSB                                           200.9 MHz  (: 200 MHz)
       HyperTransport                            2009.0 MHz
                                   2009.0 MHz
                                              803.6 MHz
       DRAM:FSB                              24:6

     :
       L1                                        64  per core
       L1                                      64  per core
       L2                                            512  per core  (On-Die, ECC, Full-Speed)

      :
      ID                                  65-1401-000001-00101111-050516-RS760_SB710$A2035001_BIOS DATE: 05/05/16 10:15:51 VER: 14.01
                                          Asus M5A78L-M LX3  (1 PCI, 1 PCI-E x1, 1 PCI-E x16, 2 DDR3 DIMM, Audio, Video, Gigabit LAN)

       ():
                                    AMD 760G, AMD K10
                                          11-11-11-28  (CL-RCD-RP-RAS)
      Command Rate (CR)                                 2T
      DIMM1: Kingston 99U5471-050.A00LF                 8  DDR3-1600 DDR3 SDRAM  (11-11-11-28 @ 800 )  (10-10-10-27 @ 761 )  (9-9-9-24 @ 685 )  (8-8-8-22 @ 609 )  (7-7-7-19 @ 533 )  (6-6-6-16 @ 457 )

     BIOS:
       BIOS                                  05/05/16
       BIOS                            07/14/16
      DMI  BIOS                                   1401

      :
                                            AMD Radeon R7 240 (Oland)
                                       Oland  (PCI Express 2.0 x8 1002 / 6617, Rev C7)
                                               300   (: 700 )
                                           300   (: 800 )


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                         
                              
                          


--------[   ]----------------------------------------------------------------------------------------------

    Centrino (Carmel)  :
      : Intel Pentium M (Banias/Dothan)                 (AMD Athlon II X3 450)
      : Intel i855GM/PM                             (AMD 760G, AMD K10)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Sonoma)  :
      : Intel Pentium M (Dothan)                        (AMD Athlon II X3 450)
      : Intel i915GM/PM                             (AMD 760G, AMD K10)
      WLAN: Intel PRO/Wireless 2200/2915                
      : Centrino-                     

    Centrino (Napa)  :
      : Intel Core (Yonah) / Core 2 (Merom)             (AMD Athlon II X3 450)
      : Intel i945GM/PM                             (AMD 760G, AMD K10)
      WLAN: Intel PRO/Wireless 3945/3965                
      : Centrino-                     

    Centrino (Santa Rosa)  :
      : Intel Core 2 (Merom/Penryn)                     (AMD Athlon II X3 450)
      : Intel GM965/PM965                           (AMD 760G, AMD K10)
      WLAN: Intel Wireless WiFi Link 4965               
      : Centrino-                     

    Centrino 2 (Montevina)  :
      : Intel Core 2 (Penryn)                           (AMD Athlon II X3 450)
      : Mobile Intel 4 Series                       (AMD 760G, AMD K10)
      WLAN: Intel WiFi Link 5000 Series                 
      : Centrino 2-                   

    Centrino (Calpella)  :
      : Intel Core i3/i5/i7 (Arrandale/Clarksfield)     (AMD Athlon II X3 450)
      : Mobile Intel 5 Series                       (AMD 760G, AMD K10)
      WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N
      : Centrino-                     

    Centrino (Huron River)  :
      : Intel Core i3/i5/i7 (Sandy Bridge-MB)           (AMD Athlon II X3 450)
      : Mobile Intel 6 Series                       (AMD 760G, AMD K10)
      WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N
      : Centrino-                     

    Centrino (Chief River)  :
      : Intel Core i3/i5/i7 (Ivy Bridge-MB)             (AMD Athlon II X3 450)
      : Mobile Intel 7 Series                       (AMD 760G, AMD K10)
      WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N
      : Centrino-                     

    Centrino (Shark Bay-MB)  :
      : Intel Core i3/i5/i7 (Haswell-MB)                (AMD Athlon II X3 450)
      : Mobile Intel 8/9 Series                     (AMD 760G, AMD K10)
      WLAN: Intel Centrino Advanced-N / Ultimate-N / Wireless-N
      : Centrino-                     


--------[  ]-----------------------------------------------------------------------------------------------------

     :
                                              ITE IT8771F  (ISA 290h)
                                            National LM96163  (ATI-I2C 4Ch)
                                          Asus M5A78L-M LE/USB3 / M5A78L-M LX3
                               

    :
                                          34 C
                                                      39 C
                                                  25 C
                                    27 C
                                                  30 C
                                             35 C
      WD5001AALS-00LWTA0                                33 C

    :
                                                      2428 RPM
                                    31%

    :
                                                  1.224 V
      CPU VID                                           1.400 V
      +3.3 V                                            3.384 V
      +5 V                                              5.100 V
      +12 V                                             12.096 V
        VID                                 1.175 V
                                                  0.875 V
      Debug Info F                                      0116 FFFF FFFF 0000 0000
      Debug Info T                                      39 34 128
      Debug Info V                                      66 BA A8 AA AB 21 EA 2D 87


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   TripleCore AMD Athlon II X3 450, 3200 MHz (16 x 200)
                                             Rana
                                              BL-C3
                                        x86, x86-64, MMX, 3DNow!, SSE, SSE2, SSE3, SSE4A
                                         3200 
      ./.                             4x / 16x
      Engineering Sample                                
       L1                                        64  per core
       L1                                      64  per core
       L2                                            512  per core  (On-Die, ECC, Full-Speed)

       :
                                              938 Pin uOPGA
                                          40 mm x 40 mm
                                       300 
                                  45 nm, CMOS, Cu, Low-K, DSL SOI, Immersion Lithography
                                         169 mm2
                                   1.400 V
       I/O                                    1.2 V + 2.5 V

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com/en/products/processors-desktop
                                     http://www.aida64.com/goto/?p=drvupdates

    Multi CPU:
      ID                                  ASUS
      CPU #1                                            AMD Athlon(tm) II X3 450 Processor, 3214 
      CPU #2                                            AMD Athlon(tm) II X3 450 Processor, 3214 
      CPU #3                                            AMD Athlon(tm) II X3 450 Processor, 3214 

     :
       1 /  1                                     25%
       1 /  2                                     25%
       1 /  3                                     0%


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               AuthenticAMD
        CPUID                                      AMD Athlon(tm) II X3 450 Processor
       CPUID                                      00100F53h
        CPUID                          00100F53h
       AMD                                 3B26h  (Athlon II X3 450)
                                  C5h  (Socket AM3)
                               010000C8h
      SMT / CMP                                         0 / 3
      HTC Temperature Limit (TctlMax)                   83 C  (181 F)

     :
      64- x86- (AMD64, Intel64)      
      AMD 3DNow!                                        
      AMD 3DNow! Professional                           
      AMD 3DNowPrefetch                                 
      AMD Enhanced 3DNow!                               
      AMD Extended MMX                                  
      AMD FMA4                                           
      AMD MisAligned SSE                                
      AMD SSE4A                                         
      AMD XOP                                            
      Cyrix Extended MMX                                 
      Enhanced REP MOVSB/STOSB                           
      Enqueue Stores                                     
      Galois Field New Instructions (GFNI)               
      Float-16 Conversion Instructions                   
      IA-64                                              
      IA AES Extensions                                  
      IA AVX                                             
      IA AVX2                                            
      IA AVX-512 (AVX512F)                               
      IA AVX-512 4x Fused Multiply-Add Single Precision (AVX512_4FMAPS) 
      IA AVX-512 4x Neural Network Instructions (AVX512_4VNNIW) 
      IA AVX-512 52-bit Integer Multiply-Add Instructions (AVX512_IFMA) 
      IA AVX-512 BF16 (AVX512_BF16)                      
      IA AVX-512 Bit Algorithm (AVX512_BITALG)           
      IA AVX-512 Byte and Word Instructions (AVX512BW)   
      IA AVX-512 Conflict Detection Instructions (AVX512CD) 
      IA AVX-512 Doubleword and Quadword Instructions (AVX512DQ) 
      IA AVX-512 Exponential and Reciprocal Instructions (AVX512ER) 
      IA AVX-512 Intersection (AVX512_VP2INTERSECT)      
      IA AVX-512 Neural Network Instructions (AVX512_VNNI) 
      IA AVX-512 Prefetch Instructions (AVX512PF)        
      IA AVX-512 Vector Bit Manipulation Instructions (AVX512_VBMI) 
      IA AVX-512 Vector Bit Manipulation Instructions 2 (AVX512_VBMI2) 
      IA AVX-512 Vector Length Extensions (AVX512VL)     
      IA AVX-512 VPOPCNTDQ                               
      IA BMI1                                            
      IA BMI2                                            
      IA FMA                                             
      IA MMX                                            
      IA SHA Extensions                                  
      IA SSE                                            
      IA SSE2                                           
      IA SSE3                                           
      IA Supplemental SSE3                               
      IA SSE4.1                                          
      IA SSE4.2                                          
      Vector AES (VAES)                                  
      VIA Alternate Instruction Set                      
       ADCX / ADOX                             
       CLDEMOTE                                
       CLFLUSH                                
       CLFLUSHOPT                              
       CLWB                                    
       CLZERO                                  
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       Fast Short REP MOV                      
       INVPCID                                 
       LAHF / SAHF                            
       LZCNT                                  
       MCOMMIT                                 
       MONITOR / MWAIT                        
       MONITORX / MWAITX                       
       MOVBE                                   
       MOVDIR64B                               
       MOVDIRI                                 
       PCLMULQDQ                               
       PCOMMIT                                 
       PCONFIG                                 
       POPCNT                                 
       PREFETCHWT1                             
       PTWRITE                                 
       RDFSBASE / RDGSBASE / WRFSBASE / WRGSBASE 
       RDPRU                                   
       RDRAND                                  
       RDSEED                                  
       RDTSCP                                 
       SKINIT / STGI                          
       SYSCALL / SYSRET                       
       SYSENTER / SYSEXIT                     
      Trailing Bit Manipulation Instructions             
       VIA FEMMS                               
       VPCLMULQDQ                              
       WBNOINVD                                

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
      Control-flow Enforcement Technology - Indirect Branch Tracking (CET_IBT) 
      Control-flow Enforcement Technology - Shadow Stack (CET_SS) 
         (DEP, NX, EDB)           
      Enhanced Indirect Branch Restricted Speculation    
      Hardware Random Number Generator (RNG)             
      Hardware Random Number Generator 2 (RNG2)          
      Indirect Branch Predictor Barrier (IBPB)           
      Indirect Branch Restricted Speculation (IBRS)      
      L1D Flush                                          
      MD_CLEAR                                           
      Memory Protection Extensions (MPX)                 
      PadLock Hash Engine (PHE)                          
      PadLock Hash Engine 2 (PHE2)                       
      PadLock Montgomery Multiplier (PMM)                
      PadLock Montgomery Multiplier 2 (PMM2)             
         (PSN)                    
      Protection Keys for User-Mode Pages (PKU)          
      Read Processor ID (RDPID)                          
      Safer Mode Extensions (SMX)                        
      Secure Memory Encryption (SME)                     
      SGX Launch Configuration (SGX_LC)                  
      Software Guard Extensions (SGX)                    
      Single Thread Indirect Branch Predictors (STIBP)   
      Speculative Store Bypass Disable (SSBD)            
      Supervisor Mode Access Prevention (SMAP)           
      Supervisor Mode Execution Protection (SMEP)        
      Total Memory Encryption (TME)                      
      User-Mode Instruction Prevention (UMIP)            

     :
      APM Power Reporting                                
      Application Power Management (APM)                 
      Automatic Clock Control                            
      Configurable TDP (cTDP)                            
      Connected Standby                                  
      Core C6 State (CC6)                                
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                         , 
      Enhanced SpeedStep Technology (EIST, ESS)          
      Frequency ID Control                               
      Hardware P-State Control                          
      Hardware Thermal Control (HTC)                    , 
      LongRun                                            
      LongRun Table Interface                            
      Overstress                                         
      Package C6 State (PC6)                             
      Parallax                                           
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                       
      Running Average Power Limit (RAPL)                 
      Software Thermal Control                          
      SpeedShift (SST, HWP)                              
                                               
      Thermal Monitor 1                                  
      Thermal Monitor 2                                  
      Thermal Monitor 3                                  
      Thermal Monitoring                                
      Thermal Trip                                      
      Voltage ID Control                                 

     :
      AMD Virtual Interrupt Controller (AVIC)            
      Decode Assists                                     
      Encrypted Microcode Patch                          
      Encrypted State (SEV-ES)                           
      Extended Page Table (EPT)                          
      Flush by ASID                                      
      Guest Mode Execute Trap Extension (GMET)           
      Hypervisor                                        
       INVEPT                                  
       INVVPID                                 
      LBR Virtualization                                
      Memory Bandwidth Enforcement (MBE)                 
      Nested Paging (NPT, RVI)                          
      NRIP Save (NRIPS)                                 
      PAUSE Filter Threshold                             
      PAUSE Intercept Filter                             
      Secure Encrypted Virtualization (SEV)              
      Secure Virtual Machine (SVM, Pacifica)            
      SVM Lock (SVML)                                   
      Virtual Transparent Encryption (VTE)               
      Virtualized GIF (vGIF)                             
      Virtualized VMLOAD and VMSAVE                      
      Virtual Machine Extensions (VMX, Vanderpool)       
      Virtual Processor ID (VPID)                        
      VMCB Clean Bits                                    

     CPUID:
      1 GB Page Size                                    
      36-bit Page Size Extension                        
      5-Level Paging                                     
      64-bit DS Area                                     
      Adaptive Overclocking                              
      Address Region Registers (ARR)                     
      Code and Data Prioritization Technology (CDP)      
      Core Performance Boost (CPB)                       
      Core Performance Counters                          
      CPL Qualified Debug Store                          
      Data Breakpoint Extension                          
      Debug Trace Store                                  
      Debugging Extension                               
      Deprecated FPU CS and FPU DS                       
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Dynamic Configurable TDP (DcTDP)                   
      Extended APIC Register Space                      
      Fast Save & Restore                               
      Hardware Lock Elision (HLE)                        
      Hybrid Boost                                       
      Hybrid CPU                                         
      Hyper-Threading Technology (HTT)                   
      Instruction Based Sampling                        
      Invariant Time Stamp Counter                      
      L1 Context ID                                      
      L2I Performance Counters                           
      Lightweight Profiling                              
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      NB Performance Counters                            
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event (PBE)                          
      Performance Time Stamp Counter (PTSC)              
      Physical Address Extension (PAE)                  
      Platform Quality of Service Enforcement (PQE)      
      Platform Quality of Service Monitoring (PQM)       
      Process Context Identifiers (PCID)                 
      Processor Feedback Interface                       
      Processor Trace (PT)                               
      Restricted Transactional Memory (RTM)              
      Self-Snoop                                         
      Time Stamp Counter (TSC)                          
      Time Stamp Counter Adjust                          
      Turbo Boost                                        
      Turbo Boost Max 3.0                                
      Virtual Mode Extension                            
      Watchdog Timer                                    
      x2APIC                                             
      XGETBV / XSETBV OS Enabled                         
      XSAVE / XRSTOR / XSETBV / XGETBV Extended States   
      XSAVEOPT                                           

    CPUID Registers (CPU #0):
      CPUID 00000000                                    00000005-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00100F53-00030800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00100F53-10003B26-000837FF-EFD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-4920296D [AMD Athlon(tm) I]
      CPUID 80000003                                    33582049-30353420-6F725020-73736563 [I X3 450 Process]
      CPUID 80000004                                    0000726F-00000000-00000000-00000000 [or]
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000001F9
      CPUID 80000008                                    00003030-00000000-00002002-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000000F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    0000001F-00000000-00000000-00000000

    CPUID Registers (CPU #1):
      CPUID 00000000                                    00000005-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00100F53-01030800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00100F53-10003B26-000837FF-EFD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-4920296D [AMD Athlon(tm) I]
      CPUID 80000003                                    33582049-30353420-6F725020-73736563 [I X3 450 Process]
      CPUID 80000004                                    0000726F-00000000-00000000-00000000 [or]
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000001F9
      CPUID 80000008                                    00003030-00000000-00002002-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000000F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    0000001F-00000000-00000000-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    00000005-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00100F53-02030800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00100F53-10003B26-000837FF-EFD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-4920296D [AMD Athlon(tm) I]
      CPUID 80000003                                    33582049-30353420-6F725020-73736563 [I X3 450 Process]
      CPUID 80000004                                    0000726F-00000000-00000000-00000000 [or]
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000001F9
      CPUID 80000008                                    00003030-00000000-00002002-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000000F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    0000001F-00000000-00000000-00000000

    MSR Registers (CPU #0):
      CPU Clock (Normal)                                3215 MHz
      CPU Clock (TSC)                                   3214 MHz
      CPU Multiplier                                    16.0x
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR 0000008B                                      0000-0000-0100-00C8
      MSR C0010004                                      0000-312B-C8F1-58EA
      MSR C0010005                                      0000-8F15-EFCD-57B3
      MSR C0010006                                      0000-EB76-E853-831E
      MSR C0010007                                      0000-0000-0000-0000
      MSR C0010015                                      0000-0000-0100-0011
      MSR C001001F                                      4258-4000-0000-0008
      MSR C0010055                                      0000-0000-0000-0000
      MSR C0010058                                      0000-0000-E000-0021
      MSR C0010061                                      0000-0000-0000-0030
      MSR C0010062                                      0000-0000-0000-0000
      MSR C0010063                                      0000-0000-0000-0000
      MSR C0010064                                      8000-0019-3C00-1810 [16.00x] [1.4000 V] [25.00 A] [PState P0]
      MSR C0010065                                      8000-01C6-3C00-2809 [12.50x] [1.3000 V] [19.80 A] [PState P1]
      MSR C0010066                                      8000-01B9-3C00-3404 [10.00x] [1.2250 V] [18.50 A] [PState P2]
      MSR C0010067                                      8000-0176-3C00-5040 [ 4.00x] [1.0500 V] [11.80 A] [PState P3]
      MSR C0010068                                      0000-0000-4000-0000
      MSR C0010070                                      0000-0000-3C00-1810
      MSR C0010071                                      30C0-0063-3C00-1810 [16.00x] [1.4000V]
      MSR C0010071                                      30C0-0063-3C00-1810 [16.00x] [1.4000V]
      MSR C0010071                                      30C0-0063-3C02-3404 [10.00x] [1.2250V]
      MSR C0010071                                      30C0-0063-3C02-3404 [10.00x] [1.2250V]
      MSR C0010071                                      30C0-0063-3C02-3404 [10.00x] [1.2250V]
      MSR C0010140                                      0000-0000-0000-0004
      MSR C0010141                                      0000-0000-0000-000C
      MSR C0011023                                      0000-0000-1020-0020

    MSR Registers (CPU #1):
      CPU Clock (Normal)                                3215 MHz
      CPU Clock (TSC)                                   3214 MHz
      CPU Multiplier                                    16.0x
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR 0000008B                                      0000-0000-0100-00C8
      MSR C0010004                                      0000-312B-C8F1-58EA
      MSR C0010005                                      0000-8F15-EFCD-57B3
      MSR C0010006                                      0000-EB76-E853-831E
      MSR C0010007                                      0000-0000-0000-0000
      MSR C0010015                                      0000-0000-0100-0011
      MSR C001001F                                      4258-4000-0000-0008
      MSR C0010055                                      0000-0000-0000-0000
      MSR C0010058                                      0000-0000-E000-0021
      MSR C0010061                                      0000-0000-0000-0030
      MSR C0010062                                      0000-0000-0000-0000
      MSR C0010063                                      0000-0000-0000-0000
      MSR C0010064                                      8000-0019-3C00-1810 [16.00x] [1.4000 V] [25.00 A] [PState P0]
      MSR C0010065                                      8000-01C6-3C00-2809 [12.50x] [1.3000 V] [19.80 A] [PState P1]
      MSR C0010066                                      8000-01B9-3C00-3404 [10.00x] [1.2250 V] [18.50 A] [PState P2]
      MSR C0010067                                      8000-0176-3C00-5040 [ 4.00x] [1.0500 V] [11.80 A] [PState P3]
      MSR C0010068                                      0000-0000-4000-0000
      MSR C0010070                                      0000-0000-3C00-1810
      MSR C0010071                                      30C0-0063-3C00-1810 [16.00x] [1.4000V]
      MSR C0010071                                      30C0-0063-3C00-1810 [16.00x] [1.4000V]
      MSR C0010071                                      30C0-0063-3C03-5040 [ 4.00x] [1.0500V]
      MSR C0010071                                      30C0-0063-3C03-5040 [ 4.00x] [1.0500V]
      MSR C0010071                                      30C0-0063-3C03-5040 [ 4.00x] [1.0500V]
      MSR C0010140                                      0000-0000-0000-0004
      MSR C0010141                                      0000-0000-0000-000C
      MSR C0011023                                      0000-0000-1020-0020

    MSR Registers (CPU #2):
      CPU Clock (Normal)                                803 MHz
      CPU Clock (TSC)                                   3214 MHz
      CPU Multiplier                                    4.0x
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR 0000008B                                      0000-0000-0100-00C8
      MSR C0010004                                      0000-312B-C8F1-58EA
      MSR C0010005                                      0000-8F15-EFCD-57B3
      MSR C0010006                                      0000-EB76-E853-831E
      MSR C0010007                                      0000-0000-0000-0000
      MSR C0010015                                      0000-0000-0100-0011
      MSR C001001F                                      4258-4000-0000-0008
      MSR C0010055                                      0000-0000-0000-0000
      MSR C0010058                                      0000-0000-E000-0021
      MSR C0010061                                      0000-0000-0000-0030
      MSR C0010062                                      0000-0000-0000-0003
      MSR C0010063                                      0000-0000-0000-0003
      MSR C0010064                                      8000-0019-3C00-1810 [16.00x] [1.4000 V] [25.00 A] [PState P0]
      MSR C0010065                                      8000-01C6-3C00-2809 [12.50x] [1.3000 V] [19.80 A] [PState P1]
      MSR C0010066                                      8000-01B9-3C00-3404 [10.00x] [1.2250 V] [18.50 A] [PState P2]
      MSR C0010067                                      8000-0176-3C00-5040 [ 4.00x] [1.0500 V] [11.80 A] [PState P3]
      MSR C0010068                                      0000-0000-4000-0000
      MSR C0010070                                      0000-0000-3C03-5040
      MSR C0010071                                      30C0-0063-3C03-5040 [ 4.00x] [1.0500V]
      MSR C0010071                                      30C0-0063-3C03-5040 [ 4.00x] [1.0500V]
      MSR C0010071                                      30C0-0063-3C03-5040 [ 4.00x] [1.0500V]
      MSR C0010071                                      30C0-0063-3C03-5040 [ 4.00x] [1.0500V]
      MSR C0010071                                      30C0-0063-3C03-5040 [ 4.00x] [1.0500V]
      MSR C0010140                                      0000-0000-0000-0004
      MSR C0010141                                      0000-0000-0000-000C
      MSR C0011023                                      0000-0000-1020-0020


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  65-1401-000001-00101111-050516-RS760_SB710$A2035001_BIOS DATE: 05/05/16 10:15:51 VER: 14.01
                                          Asus M5A78L-M LX3

      FSB:
                                                 AMD K10
                                         200 
                                      200 
       HyperTransport                            2000 
                                   2000 

      :
                                                 DDR3 SDRAM
                                              64 
       DRAM:FSB                              24:6
                                         800  (DDR)
                                      1600 
                                   12800 /

        :
                                            1 Socket AM3+
                                       1 PCI, 1 PCI-E x1, 1 PCI-E x16
                                              2 DDR3 DIMM
                                    Audio, Video, Gigabit LAN
      -                                       Micro ATX
                                   190 mm x 240 mm
                                    AMD760G

      :
                                                   ASUSTeK Computer Inc.
                                     https://www.asus.com/Motherboards
        BIOS                          https://www.asus.com/support
                                     http://www.aida64.com/goto/?p=drvupdates
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   8190 
                                                  2736 
                                                5454 
                                                33 %

     :
                                                   19188 
                                                  3882 
                                                15306 
                                                20 %

     :
                                            C:\pagefile.sys
      /                       2000  / 2000 
                                           2000 
      /                           0  / 0 
                                                0 %

     :
                                            D:\pagefile.sys
      /                       9000  / 9000 
                                           9000 
      /                           0  / 0 
                                                0 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[ SPD ]---------------------------------------------------------------------------------------------------------

  [ DIMM1: Kingston 99U5471-050.A00LF ]

      :
                                               Kingston 99U5471-050.A00LF
                                           1420117Bh (2064719892)
                                              7 / 2020
                                            8  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR3 SDRAM
                                          DDR3-1600 (800 )
                                            64 bit
                                        1.35 V / 1.5 V
                                  
                                       (7.8 us)

     :
      @ 800                                          11-11-11-28  (CL-RCD-RP-RAS) / 39-208-5-12-6-6-24  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 761                                          10-10-10-27  (CL-RCD-RP-RAS) / 37-199-5-12-6-6-23  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 685                                          9-9-9-24  (CL-RCD-RP-RAS) / 33-179-5-11-6-6-21  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 609                                          8-8-8-22  (CL-RCD-RP-RAS) / 30-159-4-10-5-5-19  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 533                                          7-7-7-19  (CL-RCD-RP-RAS) / 26-139-4-8-4-4-16  (RC-RFC-RRD-WR-WTR-RTP-FAW)
      @ 457                                          6-6-6-16  (CL-RCD-RP-RAS) / 22-119-3-7-4-4-14  (RC-RFC-RRD-WR-WTR-RTP-FAW)

      :
      Auto Self Refresh (ASR)                            
      DLL-Off Mode                                      
      Extended Temperature Range                        
      Extended Temperature 1X Refresh Rate               
      Module Thermal Sensor                              
      On-Die Thermal Sensor Readout (ODTS)               
      Partial Array Self Refresh (PASR)                 
      RZQ/6                                             
      RZQ/7                                             

      :
                                                   Kingston Technology Corporation
                                     https://www.kingston.com/en/memory


--------[  ]------------------------------------------------------------------------------------------------------

  [  : AMD RS780L ]

      :
                                            AMD RS780L
                                                  00
                                              528 Ball FC-BGA
                                          21 mm x 21 mm
                                       205 
                                  55 nm
                                   1.0 V

     PCI Express:
      PCI-E 2.0 x16 port #0                              @ x8  (AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller, AMD Radeon R7 240 (Oland) Video Adapter)
      PCI-E 2.0 x1 port #1                               @ x1  (Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller)

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/support
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates
                                     http://www.aida64.com/goto/?p=drvupdates

  [  : AMD K10 IMC ]

      :
                                            AMD K10 IMC
                                DDR2-400, DDR2-533, DDR2-667, DDR2-800, DDR2-1066, DDR3-800, DDR3-1066, DDR3-1333 SDRAM
                                                  00
                                  45 nm
      Probe Filter                                       

     :
                                                     Dual Channel  (128 )
                                           Single Channel  (64 )

     :
      CAS Latency (CL)                                  11T
      RAS To CAS Delay (tRCD)                           11T
      RAS Precharge (tRP)                               11T
      RAS Active Time (tRAS)                            28T
      Row Cycle Time (tRC)                              39T
      Command Rate (CR)                                 2T
      RAS To RAS Delay (tRRD)                           5T
      Write Recovery Time (tWR)                         12T
      Read To Read Delay (tRTR)                         Different Rank: 3T
      Write To Read Delay (tWTR)                        6T, Different DIMM: 2T
      Write To Write Delay (tWTW)                       Different Rank: 3T
      Read To Precharge Delay (tRTP)                    6T
      Four Activate Window Delay (tFAW)                 24T
      Write CAS Latency (tWCL)                          8T
      Refresh Period (tREF)                             7.8 us
      DRAM Drive Strength                               1.0x
      DRAM Data Drive Strength                          1.0x
      Clock Drive Strength                              1.5x
      CKE Drive Strength                                1.5x
      Idle Cycle Limit                                  16
      Burst Length (BL)                                 64

     :
      ECC                                               , 
      ChipKill ECC                                      , 
      RAID                                               
      DRAM Scrub Rate                                   
      L1 Data Cache Scrub Rate                          5.24 ms
      L2 Cache Scrub Rate                               1.31 ms
      L3 Cache Scrub Rate                               

     :
       DRAM 1                                     8   (DDR3 SDRAM)

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/support
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates
                                     http://www.aida64.com/goto/?p=drvupdates

  [  : AMD SB710 ]

      :
                                               AMD SB710
                                                  00
                                              528 Ball FC-BGA
                                          21 mm x 21 mm
                                  130 nm
                                   1.2 V

    High Definition Audio:
                                               Realtek ALC887
      ID                                          10EC0887h / 10438445h
                                            1003h
                                               Audio

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/support
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates
                                     http://www.aida64.com/goto/?p=drvupdates


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          AMI
       BIOS                                       1401
      SMBIOS Version                                    2.5
      UEFI Boot                                         
      Secure Boot                                        
       BIOS                                  05/05/16
       BIOS                            07/14/16

     BIOS (ATK):
      CPU Voltage                                       0.8000 V
      CPU/NB Voltage                                    1.200 V
      CPU Frequency                                     200.00 MHz
      CPU Ratio                                         20.0x

     BIOS:
                                                   American Megatrends Inc.
                                     https://ami.com/en/products/bios-uefi-firmware
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates


--------[ ACPI ]--------------------------------------------------------------------------------------------------------

  [ APIC: Multiple APIC Description Table ]

      ACPI:
       ACPI                                      APIC
                                         Multiple APIC Description Table
                                             CFE80390h
                                           140 
      OEM ID                                            050516
      OEM Table ID                                      APIC1015
      OEM Revision                                      20160505h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      Local APIC Address                                FEE00000h

    Processor Local APIC:
      ACPI Processor ID                                 01h
      APIC ID                                           00h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 02h
      APIC ID                                           01h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 03h
      APIC ID                                           02h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 04h
      APIC ID                                           83h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 05h
      APIC ID                                           84h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 06h
      APIC ID                                           85h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 07h
      APIC ID                                           86h
                                                  

    Processor Local APIC:
      ACPI Processor ID                                 08h
      APIC ID                                           87h
                                                  

    I/O APIC:
      I/O APIC ID                                       03h
      I/O APIC Address                                  FEC00000h
      Global System Interrupt Base                      00000000h

    Interrupt Source Override:
                                                    ISA
                                                IRQ0
      Global System Interrupt                           00000002h
                                              Conforms to the specifications of the bus
      Trigger Mode                                      Conforms to the specifications of the bus

    Interrupt Source Override:
                                                    ISA
                                                IRQ9
      Global System Interrupt                           00000009h
                                              Active Low
      Trigger Mode                                      Level-Triggered

  [ DSDT: Differentiated System Description Table ]

      ACPI:
       ACPI                                      DSDT
                                         Differentiated System Description Table
                                             CFE80460h
                                           54249 
      OEM ID                                            A2035
      OEM Table ID                                      A2035001
      OEM Revision                                      00000001h
      Creator ID                                        INTL
      Creator Revision                                  20060113h

    nVIDIA SLI:
      SLI Certification                                 
      PCI 0-0-0-0 (Direct I/O)                          1022-9600
      PCI 0-0-0-0 (HAL)                                 1022-9600

    Lucid Virtu:
      Virtu Certification                               

  [ FACP: Fixed ACPI Description Table ]

      ACPI:
       ACPI                                      FACP
                                         Fixed ACPI Description Table
                                             CFE80200h
                                           132 
      OEM ID                                            050516
      OEM Table ID                                      FACP1015
      OEM Revision                                      20160505h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      FACS Address                                      CFE98000h
      DSDT Address                                      CFE80460h
      SMI Command Port                                  000000B0h
      PM Timer                                          00000808h

  [ FACP: Fixed ACPI Description Table ]

      ACPI:
       ACPI                                      FACP
                                         Fixed ACPI Description Table
                                             00000000-CFE80290h
                                           244 
      OEM ID                                            050516
      OEM Table ID                                      FACP1015
      OEM Revision                                      20160505h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      FACS Address                                      CFE98000h / 00000000-CFE98000h
      DSDT Address                                      CFE80460h / 00000000-CFE80460h
      SMI Command Port                                  000000B0h
      PM Timer                                          00000808h

  [ FACS: Firmware ACPI Control Structure ]

      ACPI:
       ACPI                                      FACS
                                         Firmware ACPI Control Structure
                                             CFE98000h
                                           64 
      Hardware Signature                                00000000h
      Waking Vector                                     00000000h
      Global Lock                                       00000000h

  [ HPET: IA-PC High Precision Event Timer Table ]

      ACPI:
       ACPI                                      HPET
                                         IA-PC High Precision Event Timer Table
                                             CFE8F460h
                                           56 
      OEM ID                                            050516
      OEM Table ID                                      OEMHPET
      OEM Revision                                      20160505h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      HPET Address                                      00000000-FED00000h
      ID                                      0000h
                                                  00h
      Number of Timers                                  4
      Counter Size                                      32 
      Minimum Clock Ticks                               20
      Page Protection                                   No Guarantee
      OEM Attribute                                     0h
      LegacyReplacement IRQ Routing                     

  [ MCFG: Memory Mapped Configuration Space Base Address Description Table ]

      ACPI:
       ACPI                                      MCFG
                                         Memory Mapped Configuration Space Base Address Description Table
                                             CFE80420h
                                           60 
      OEM ID                                            050516
      OEM Table ID                                      OEMMCFG
      OEM Revision                                      20160505h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      Config Space Address                              00000000-E0000000h
      PCI Segment                                       0000h
      Start Bus Number                                  00h
      End Bus Number                                    FFh

  [ OEMB: OEM Specific Information Table ]

      ACPI:
       ACPI                                      OEMB
                                         OEM Specific Information Table
                                             CFE98040h
                                           114 
      OEM ID                                            050516
      OEM Table ID                                      OEMB1015
      OEM Revision                                      20160505h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ RSD PTR: Root System Description Pointer ]

      ACPI:
       ACPI                                      RSD PTR
                                         Root System Description Pointer
                                             000FBA40h
                                           36 
      OEM ID                                            ACPIAM
      RSDP Revision                                     2  (ACPI 2.0+)
      RSDT Address                                      CFE80000h
      XSDT Address                                      00000000-CFE80100h

  [ RSDT: Root System Description Table ]

      ACPI:
       ACPI                                      RSDT
                                         Root System Description Table
                                             CFE80000h
                                           64 
      OEM ID                                            ACRSYS
      OEM Table ID                                      ACRPRDCT
      OEM Revision                                      20160505h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      RSDT Entry #0                                     CFE80200h  (FACP)
      RSDT Entry #1                                     CFE80390h  (APIC)
      RSDT Entry #2                                     CFE80420h  (MCFG)
      RSDT Entry #3                                     CFE98040h  (OEMB)
      RSDT Entry #4                                     CFE8F460h  (HPET)
      RSDT Entry #5                                     CFE8F4A0h  (SSDT)
      RSDT Entry #6                                     CFE98730h  (SLIC)

  [ SLIC: Software Licensing Description Table ]

      ACPI:
       ACPI                                      SLIC
                                         Software Licensing Description Table
                                             CFE98730h
                                           374 
      OEM ID                                            ACRSYS
      OEM Table ID                                      ACRPRDCT
      OEM Revision                                      00000001h
      Creator ID                                        ANNI
      Creator Revision                                  00000001h
       SLIC                                       v2.1

    OEM Public Key:
      Key Type                                          06h
                                                  02h
      Algorithm                                         00002400h
      Magic                                             RSA1
      Bit Length                                        1024
      Exponent                                          65537

    SLIC Marker:
                                                  00020001h
      OEM ID                                            ACRSYS
      OEM Table ID                                      ACRPRDCT
      Windows Flag                                      WINDOWS

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             CFE8F4A0h
                                           1686 
      OEM ID                                            A M I
      OEM Table ID                                      POWERNOW
      OEM Revision                                      00000001h
      Creator ID                                        AMD
      Creator Revision                                  00000001h

  [ XSDT: Extended System Description Table ]

      ACPI:
       ACPI                                      XSDT
                                         Extended System Description Table
                                             00000000-CFE80100h
                                           92 
      OEM ID                                            ACRSYS
      OEM Table ID                                      ACRPRDCT
      OEM Revision                                      20160505h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      XSDT Entry #0                                     00000000-CFE80290h  (FACP)
      XSDT Entry #1                                     00000000-CFE80390h  (APIC)
      XSDT Entry #2                                     00000000-CFE80420h  (MCFG)
      XSDT Entry #3                                     00000000-CFE98040h  (OEMB)
      XSDT Entry #4                                     00000000-CFE8F460h  (HPET)
      XSDT Entry #5                                     00000000-CFE8F4A0h  (SSDT)
      XSDT Entry #6                                     00000000-CFE98730h  (SLIC)


--------[   ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                                   ()
                                        ()
                                               Multiprocessor Free (64-bit)
                                                6.1.7601.19160 (Win7 RTM)
                                       Service Pack 1
                                         20.01.2020
                                         C:\Windows

     :
                          Home
                           
      ID                                        00426-OEM-8992662-00006
                                            FJGCP-4DFJD-GJY49-VJBQ7-HYRR2
        (WPA)                           

     :
                                           HOME-
                                         Home
                                              Home-
                                             381  (0 ., 0 , 6 , 21 )

     :
      Common Controls                                   6.16
      Windows Mail                                      6.1.7600.16385 (win7_rtm.090713-1255)
       Windows Media                       12.0.7600.16385 (win7_rtm.090713-1255)
      Windows Messenger                                 -
      MSN Messenger                                     -
      Internet Information Services (IIS)               -
      .NET Framework                                    4.7.3062.0 built by: NET472REL1
       Novell                                     -
      DirectX                                           DirectX 11.1
      OpenGL                                            6.1.7600.16385 (win7_rtm.090713-1255)
      ASPI                                              -

      :
                                        
       DBCS                                       
                                        
                                     
                                             
                                         
                                         
                                      
                                      


--------[  ]----------------------------------------------------------------------------------------------------

    aida64.exe               C:\Program Files (x86)\AIDA64\aida64.exe                                      32         80308             77 
    amdow.exe                C:\Program Files\AMD\CNext\CNext\amdow.exe                                    64          1048              2 
    AMDRSServ.exe            C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe                                64         22220             91 
    atieclxx.exe             C:\Windows\system32\atieclxx.exe                                              64          8172              2 
    atiesrxx.exe             C:\Windows\system32\atiesrxx.exe                                              64          5196              1 
    audiodg.exe                                                                                            64         18376             17 
    AUEPLauncher.exe         C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe              64          4580              1 
    AUEPMaster.exe           C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe                64         19748             11 
    AUEPUF.exe               C:\Program Files\AMD\Performance Profile Client\AUEPUF.exe                    64          7008              1 
    BlueScreenView.exe       C:\Users\Home\Desktop\ \bluescreenview-x64\BlueScreenView.exe  64         10676              5 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64          4516              2 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64         14200              2 
    dwm.exe                  C:\Windows\system32\Dwm.exe                                                   64         36456             32 
    explorer.exe             C:\Windows\Explorer.EXE                                                       64         67084             41 
    lsass.exe                C:\Windows\system32\lsass.exe                                                 64         12228              4 
    lsm.exe                  C:\Windows\system32\lsm.exe                                                   64          4524              2 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64         80548             29 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64           231            128 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64         45572             26 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64           193            175 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64         25244             14 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64           298            249 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64         61964             20 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64         16132             11 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64            97             41 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64           161            101 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64           112             54 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64           165            105 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64         87924             36 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64         76772             26 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64           135             74 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64         25132             15 
    opera.exe                D:\Opera\66.0.3515.36\opera.exe                                               64           108             53 
    opera_crashreporter.exe  D:\Opera\66.0.3515.36\opera_crashreporter.exe                                 64          5984              2 
    RadeonSoftware.exe       C:\Program Files\AMD\CNext\CNext\Radeonsoftware.exe                           64            92            106 
    RtkNGUI64.exe            C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe                              64         10232             12 
    SearchFilterHost.exe     C:\Windows\system32\SearchFilterHost.exe                                      64          6236              2 
    SearchIndexer.exe        C:\Windows\system32\SearchIndexer.exe                                         64         22824             24 
    SearchProtocolHost.exe   C:\Windows\system32\SearchProtocolHost.exe                                    64          8444              2 
    services.exe             C:\Windows\system32\services.exe                                              64          9120              5 
    smss.exe                                                                                               64          1208              0 
    splwow64.exe             C:\Windows\splwow64.exe                                                       64          4896              1 
    spoolsv.exe              C:\Windows\System32\spoolsv.exe                                               64         11740              6 
    sppsvc.exe               C:\Windows\system32\sppsvc.exe                                                64          8016              2 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          5640              2 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         14956             12 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         15080             11 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          5764              1 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         52568             73 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          6032              2 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         18036             20 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64            88             85 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         13904              6 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         27644             15 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         10184              4 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          7608              3 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          5512              2 
    System Idle Process                                                                                                     24              0 
    System                                                                                                 64           860              0 
    taskeng.exe              C:\Windows\system32\taskeng.exe                                               64          6044              2 
    taskeng.exe              C:\Windows\system32\taskeng.exe                                               64          6072              2 
    taskhost.exe             C:\Windows\system32\taskhost.exe                                              64         13388             11 
    TeamViewer_Service.exe   C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe                      32         15452              4 
    wininit.exe              C:\Windows\system32\wininit.exe                                               64          4656              1 
    winlogon.exe             C:\Windows\system32\winlogon.exe                                              64          7680              3 
    WmiApSrv.exe             C:\Windows\system32\wbem\WmiApSrv.exe                                         64          6264              1 
    WmiPrvSE.exe             C:\Windows\sysWOW64\wbem\wmiprvse.exe                                         64          7260              2 
    WmiPrvSE.exe             C:\Windows\system32\wbem\wmiprvse.exe                                         64         30068             22 
    WmiPrvSE.exe             C:\Windows\system32\wbem\wmiprvse.exe                                         64          9760              3 


--------[   ]------------------------------------------------------------------------------------------

    1394ohci         1394 OHCI- -                                   1394ohci.sys          6.1.7601.17514                        
    ACPI              Microsoft ACPI                                                  ACPI.sys              6.1.7601.17514                        
    AcpiPmi              ACPI                              acpipmi.sys           6.1.7601.17514                        
    adp94xx          adp94xx                                                                 adp94xx.sys           1.6.6.4                               
    adpahci          adpahci                                                                 adpahci.sys           1.6.6.1                               
    adpu320          adpu320                                                                 adpu320.sys           7.2.0.0                               
    AFD              Ancillary Function Driver for Winsock                                   afd.sys               6.1.7601.19031                        
    agp440           Intel -   AGP                                                 agp440.sys            6.1.7600.16385                        
    AIDA64Driver     FinalWire AIDA64 Kernel Driver                                          kerneld.x64                                                 
    aliide           aliide                                                                  aliide.sys            1.2.0.0                               
    amdide           amdide                                                                  amdide.sys            6.1.7600.16385                        
    amdide64         amdide64                                                                amdide64.sys          5.2.2.179                             
    AmdK8            AMD K8                                                 amdk8.sys             6.1.7600.16385                        
    amdkmdag         amdkmdag                                                                atikmdag.sys          26.20.15029.27016                       
    amdkmdap         amdkmdap                                                                atikmpag.sys          26.20.15029.27016                       
    AmdPPM             AMD                                                  amdppm.sys            6.1.7600.16385                        
    amdsata          amdsata                                                                 amdsata.sys           1.1.2.5                               
    amdsbs           amdsbs                                                                  amdsbs.sys            3.6.1540.127                          
    amdxata          amdxata                                                                 amdxata.sys           1.1.2.5                               
    AODDriver4.3.0   AODDriver4.3.0                                                          AODDriver2.sys        4.3.0.0                               
    AppID             AppID                                                           appid.sys             6.1.7601.19021                        
    arc              arc                                                                     arc.sys               5.2.0.10384                           
    arcsas           arcsas                                                                  arcsas.sys            5.2.0.16119                           
    AsyncMac            RAS                                       asyncmac.sys          6.1.7600.16385                        
    atapi             IDE                                                               atapi.sys             6.1.7600.16385                        
    AtiHDAudioService  AMD Function Driver for HD Audio Service                                AtihdW76.sys          7.12.0.7733                           
    b06bdrv          Broadcom NetXtreme II VBD                                               bxvbda.sys            4.8.2.0                               
    b57nd60a         Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0                          b57nd60a.sys          10.100.4.0                            
    Beep             Beep                                                                                                                                
    blbdrive         blbdrive                                                                blbdrive.sys          6.1.7600.16385                        
    bowser                                                           bowser.sys            6.1.7601.17565             
    BrFiltLo          Brother USB Mass-Storage Lower Filter                           BrFiltLo.sys          1.10.0.2                              
    BrFiltUp          Brother USB Mass-Storage Upper Filter                           BrFiltUp.sys          1.4.0.1                               
    Brserid          Brother MFC, WDM-                Brserid.sys           1.0.1.6                               
    BrSerWdm         Brother WDM Serial                                               BrSerWdm.sys          1.0.0.20                              
    BrUsbMdm         Brother MFC USB Fax Only                                           BrUsbMdm.sys          1.0.0.12                              
    BrUsbSer         Brother MFC, WDM-  USB-                    BrUsbSer.sys          1.0.1.3                               
    BTHMODEM                Bluetooth      bthmodem.sys          6.1.7600.16385                        
    cdfs             CD/DVD File System Reader                                               cdfs.sys              6.1.7600.16385             
    cdrom            cdrom                                                                   cdrom.sys             6.1.7601.17514                        
    circlass          -                                           circlass.sys          6.1.7600.16385                        
    CLFS               (CLFS)                                                     CLFS.sys              6.1.7601.18777                        
    CmBatt              ACPI- (Microsoft)                          CmBatt.sys            6.1.7600.16385                        
    cmdide           cmdide                                                                  cmdide.sys            2.0.7.0                               
    CNG              CNG                                                                     cng.sys               6.1.7601.19012                        
    Compbatt             ()                              compbatt.sys          6.1.7600.16385                        
    CompositeBus                                          CompositeBus.sys      6.1.7601.17514                        
    crcdisk            Crcdisk                                                 crcdisk.sys           6.1.7600.16385                        
    CSC                                                               csc.sys               6.1.7601.17514                        
    DfsC             DFS Namespace Client Driver                                             dfsc.sys              6.1.7601.17514             
    discache         System Attribute Cache                                                  discache.sys          6.1.7600.16385                        
    Disk                                                                         disk.sys              6.1.7600.16385                        
    dmvsc            dmvsc                                                                   dmvsc.sys             6.1.7601.17514                        
    drmkaud                                                 drmkaud.sys           6.1.7601.19091                        
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           6.1.7601.18510                        
    E1G60              Intel(R) PRO/1000 NDIS 6                               E1G6032E.sys          8.4.1.0                               
    ebdrv            Broadcom NetXtreme II 10 GigE VBD                                       evbda.sys             4.8.13.0                              
    elxstor          elxstor                                                                 elxstor.sys           7.2.10.211                            
    ErrDev               (Microsoft)                        errdev.sys            6.1.7600.16385                        
    ESProtectionDriver  Malwarebytes Anti-Exploit                                               mbae64.sys                                                  
    exfat            exFAT File System Driver                                                                                                 
    FairplayKD       FairplayKD                                                              MTA                                                         
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc                                                        fdc.sys               6.1.7600.16385                        
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          6.1.7600.16385             
    Filetrace        Filetrace                                                               filetrace.sys         6.1.7600.16385             
    flpydisk                                                     flpydisk.sys          6.1.7600.16385                        
    FltMgr                                                                  fltmgr.sys            6.1.7601.17514             
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         6.1.7600.16385             
    fvevol               Bitlocker                              fvevol.sys            6.1.7601.18062                        
    gagp30kx         Microsoft  AGPv3.0     K8-   gagp30kx.sys          6.1.7600.16385                        
    hcw85cir         Hauppauge Consumer Infrared Receiver                                    hcw85cir.sys          1.31.27127.0                          
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           6.1.7601.17514                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          6.1.7601.17514                        
    HidBatt             HID                                                 HidBatt.sys           6.1.7600.16385                        
    HidBth           Microsoft Bluetooth HID                                         hidbth.sys            6.1.7600.16385                        
    HidIr            Microsoft Infrared HID                                           hidir.sys             6.1.7600.16385                        
    HidUsb             HID Microsoft                                            hidusb.sys            6.1.7601.17514                        
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            6.12.6.64                             
    HTTP             HTTP                                                                    HTTP.sys              6.1.7601.18772                        
    HWiNFO           HWiNFO Kernel Driver                                                    HWiNFO64A.SYS         10.42.0.0                             
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          6.1.7601.17514                        
    i8042prt          i8042-     PS/2                          i8042prt.sys          6.1.7600.16385                        
    iaStorV          iaStorV                                                                 iaStorV.sys           8.6.2.1014                            
    iirsp            iirsp                                                                   iirsp.sys             5.4.22.0                              
    IntcAzAudAddService  Service for Realtek HD Audio (WDM)                                      RTKVHD64.sys          6.0.1.7179                            
    intelide         intelide                                                                intelide.sys          6.1.7600.16385                        
    intelppm          Intel                                                 intelppm.sys          6.1.7600.16385                        
    IpFilterDriver     IP-                                              ipfltdrv.sys          6.1.7601.17514                        
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           6.1.7601.17514                        
    IPNAT            IP Network Address Translator                                           ipnat.sys             6.1.7600.16385                        
    IRENUM           IR Bus Enumerator                                                       irenum.sys            6.1.7600.16385                        
    isapnp           isapnp                                                                  isapnp.sys            6.1.7600.16385                        
    iScsiPrt          iScsiPort                                                       msiscsi.sys           6.1.7601.18386                        
    kbdclass                                                          kbdclass.sys          6.1.7600.16385                        
    kbdhid             HID                                                  kbdhid.sys            6.1.7601.17514                        
    KSecDD           KSecDD                                                                  ksecdd.sys            6.1.7601.19160                        
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           6.1.7601.19160                        
    ksthunk          Kernel Streaming Thunks                                                 ksthunk.sys           6.1.7600.16385                        
    L1C              NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller  L1C62x64.sys          2.1.0.21                              
    lltdio           Link-Layer Topology Discovery Mapper I/O Driver                         lltdio.sys            6.1.7600.16385                        
    LSI_FC           LSI_FC                                                                  lsi_fc.sys            1.28.3.52                             
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.28.3.52                             
    LSI_SAS2         LSI_SAS2                                                                lsi_sas2.sys          2.0.2.71                              
    LSI_SCSI         LSI_SCSI                                                                lsi_scsi.sys          1.28.3.67                             
    luafv                                            luafv.sys             6.1.7600.16385             
    MBAMFarflt       MBAMFarflt                                                              farflt.sys                                       
    megasas          megasas                                                                 megasas.sys           4.5.1.64                              
    MegaSR           MegaSR                                                                  MegaSR.sys            13.5.409.2009                         
    Modem            Modem                                                                   modem.sys             6.1.7600.16385                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           6.1.7600.16385                        
    mouclass                                                                mouclass.sys          6.1.7600.16385                        
    mouhid             HID                                                        mouhid.sys            6.1.7600.16385                        
    mountmgr                                                        mountmgr.sys          6.1.7601.18933                        
    mpio             mpio                                                                    mpio.sys              6.1.7601.17514                        
    mpsdrv              Windows                                 mpsdrv.sys            6.1.7600.16385                        
    MRxDAV              WebDav                                 mrxdav.sys            6.1.7601.19113             
    mrxsmb              - SMB                              mrxsmb.sys            6.1.7601.19160             
    mrxsmb10         - SMB 1.x                                            mrxsmb10.sys          6.1.7601.19160             
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          6.1.7601.19160             
    msahci           msahci                                                                  msahci.sys            6.1.7601.17514                        
    msdsm            msdsm                                                                   msdsm.sys             6.1.7601.17514                        
    Msfs             Msfs                                                                                                                     
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         6.1.7600.16385                        
    msisadrv         msisadrv                                                                msisadrv.sys          6.1.7600.16385                        
    MSKSSRV             Microsoft                                   MSKSSRV.sys           6.1.7600.16385                        
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          6.1.7600.16385                        
    MSPQM                Microsoft                     MSPQM.sys             6.1.7600.16385                        
    MsRPC            MsRPC                                                                                                                               
    mssmbios         Microsoft System Management BIOS                                 mssmbios.sys          6.1.7600.16385                        
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             6.1.7600.16385                        
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          6.1.7600.16385                        
    MTsensor         ATK0110 ACPI UTILITY                                                    ASACPI.sys            1043.6.0.0                            
    Mup              Mup                                                                     mup.sys               6.1.7600.16385             
    NativeWifiP      NativeWiFi Filter                                                       nwifi.sys             6.1.7600.16385                        
    NDIS               NDIS                                                  ndis.sys              6.1.7601.19030                        
    NdisCap          NDIS Capture LightWeight Filter                                         ndiscap.sys           6.1.7600.16385                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          6.1.7600.16385                        
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           6.1.7601.17514                        
    NdisWan          NDIS- WAN                                       ndiswan.sys           6.1.7601.17514                        
    NDProxy          NDIS Proxy                                                                                                                          
    NetBIOS          NetBIOS Interface                                                       netbios.sys           6.1.7600.16385             
    NetBT            NetBT                                                                   netbt.sys             6.1.7601.17514                        
    nfrd960          nfrd960                                                                 nfrd960.sys           7.10.0.0                              
    Npfs             Npfs                                                                                                                     
    nsiproxy         NSI proxy service driver.                                               nsiproxy.sys          6.1.7600.16385                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nv_agp           NVIDIA nForce   AGP                                           nv_agp.sys            6.1.7600.16385                        
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.18                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.18                             
    ohci1394         1394 OHCI- - ( )               ohci1394.sys          6.1.7600.16385                        
    Parport                                                         parport.sys           6.1.7600.16385                        
    partmgr                                                                 partmgr.sys           6.1.7601.17796                        
    pci               PCI                                                         pci.sys               6.1.7601.17514                        
    pciide           pciide                                                                  pciide.sys            6.1.7600.16385                        
    pcmcia           pcmcia                                                                  pcmcia.sys            6.1.7600.16385                        
    pcw              Performance Counters for Windows Driver                                 pcw.sys               6.1.7600.16385                        
    PEAUTH           PEAUTH                                                                  peauth.sys            6.1.7601.18741                        
    PptpMiniport     - WAN (PPTP)                                                    raspptp.sys           6.1.7601.17514                        
    Processor                                                               processr.sys          6.1.7600.16385                        
    Psched             QoS                                                 pacer.sys             6.1.7601.17514                        
    ql2300           ql2300                                                                  ql2300.sys            9.1.8.6                               
    ql40xx           ql40xx                                                                  ql40xx.sys            2.1.3.20                              
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          6.1.7600.16385                        
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            6.1.7600.16385                        
    RasAgileVpn      WAN Miniport (IKEv2)                                                    AgileVpn.sys          6.1.7600.16385                        
    Rasl2tp          - WAN (L2TP)                                                    rasl2tp.sys           6.1.7601.17514                        
    RasPppoe          PPPOE                                          raspppoe.sys          6.1.7600.16385                        
    RasSstp          - WAN (SSTP)                                                    rassstp.sys           6.1.7600.16385                        
    rdbss                                               rdbss.sys             6.1.7601.17514             
    rdpbus           Remote Desktop Device Redirector Bus Driver                             rdpbus.sys            6.1.7600.16385                        
    RDPCDD           RDPCDD                                                                  RDPCDD.sys            6.1.7600.16385                        
    RDPDR            Terminal Server Device Redirector Driver                                rdpdr.sys             6.1.7601.17514                        
    RDPENCDD         RDP Encoder Mirror Driver                                               rdpencdd.sys          6.1.7600.16385                        
    RDPREFMP         Reflector Display Driver used to gain access to graphics data           rdprefmp.sys          6.1.7600.16385                        
    RdpVideoMiniport  Remote Desktop Video Miniport Driver                                    rdpvideominiport.sys  6.2.9200.16398                        
    RDPWD            RDP Winstation Driver                                                                                                               
    rdyboost         ReadyBoost                                                              rdyboost.sys          6.1.7601.17514                        
    rspndr           Link-Layer Topology Discovery Responder                                 rspndr.sys            6.1.7600.16385                        
    s3cap            s3cap                                                                   vms3cap.sys           6.1.7601.17514                        
    SaferVPNmmfilter  SaferVPNmmfilter                                                        SaferVPNmmfilter.sys                                        
    SaferVPNNetfilter2  SaferVPNNetfilter2                                                      SaferVPNNetfilter2.sys                                        
    sbp2port         sbp2port                                                                sbp2port.sys          6.1.7601.17514                        
    scfilter           -  PnP                                  scfilter.sys          6.1.7601.17514                        
    secdrv           Security Driver                                                                                                                     
    Serenum          Nuvoton Serenum Filter Driver                                           nuvserenum.sys        6.1.7600.16385                        
    Serial           Nuvoton Serial driver                                                   nuvserial.sys         1.0.2011.1109                         
    sermouse            .                                             sermouse.sys          6.1.7600.16385                        
    sffdisk            SFF Storage                                              sffdisk.sys           6.1.7600.16385                        
    sffp_mmc            SFF  MMC                                  sffp_mmc.sys          6.1.7600.16385                        
    sffp_sd            SFF Storage  SDBus                                 sffp_sd.sys           6.1.7601.17514                        
    sfloppy                                                            sfloppy.sys           6.1.7600.16385                        
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    Smb                TCP/IP  TCP/IPv6 ( SMB)                        smb.sys               6.1.7600.16385                        
    spldr            Security Processor Loader Driver                                                                                                    
    srv                Server SMB 1.xxx                                        srv.sys               6.1.7601.17608             
    srv2               Server SMB 2.xxx                                        srv2.sys              6.1.7601.17608             
    srvnet           srvnet                                                                  srvnet.sys            6.1.7601.17608             
    stexstor         stexstor                                                                stexstor.sys          5.0.1.1                               
    storflt                                   vmstorfl.sys          6.1.7601.17514                        
    storvsc          storvsc                                                                 storvsc.sys           6.1.7601.17514                        
    swenum                                                             swenum.sys            6.1.7600.16385                        
    Synth3dVsc       Microsoft Virtual 3D Video Transport Driver                             Synth3dVsc.sys        6.1.7601.17514                        
    tap0901          TAP-Windows Adapter V9                                                  tap0901.sys           9.0.0.21                              
    Tcpip              TCP/IP                                                tcpip.sys             6.1.7601.18438                        
    TCPIP6           Microsoft IPv6 Protocol Driver                                          tcpip.sys             6.1.7601.18438                        
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          6.1.7601.17964                        
    TDPIPE           TDPIPE                                                                  tdpipe.sys            6.1.7600.16385                        
    TDTCP            TDTCP                                                                   tdtcp.sys             6.1.7601.17779                        
    tdx                NetIO Legacy TDI                                      tdx.sys               6.1.7601.19031                        
    TermDD                                                         termdd.sys            6.1.7601.17514                        
    terminpt         Microsoft Remote Desktop Input Driver                                   terminpt.sys          6.2.9200.16398                        
    tssecsrv         Remote Desktop Services Security Filter Driver                          tssecsrv.sys          6.1.7601.18951                        
    TsUsbFlt         TsUsbFlt                                                                tsusbflt.sys          6.3.9600.16415                        
    TsUsbGD          Remote Desktop Generic USB Device                                       TsUsbGD.sys           6.3.9600.16415                        
    tsusbhub         Remote Deskotop USB Hub                                                 tsusbhub.sys          6.1.7601.17514                        
    tunnel                Microsoft                        tunnel.sys            6.1.7601.17514                        
    uagp35           Microsoft AGPv3.5                                                 uagp35.sys            6.1.7600.16385                        
    udfs             udfs                                                                    udfs.sys              6.1.7601.17514             
    uliagpkx         Uli-   AGP                                                    uliagpkx.sys          6.1.7600.16385                        
    umbus            UMBus                                               umbus.sys             6.1.7601.17514                        
    UmPass            UMPass Microsoft                                                umpass.sys            6.1.7600.16385                        
    usbaudio           USB (WDM)                                                 usbaudio.sys          6.1.7601.18208                        
    usbccgp              USB (Microsoft)         usbccgp.sys           6.1.7601.18328                        
    usbcir           eHome   (USBCIR)                                     usbcir.sys            6.1.7601.18208                        
    usbehci            Microsoft USB 2.0  -       usbehci.sys           6.1.7601.18328                        
    usbhub             USB- ()                      usbhub.sys            6.1.7601.18328                        
    usbohci            Microsoft USB  -              usbohci.sys           6.1.7601.18328                        
    usbprint           Microsoft USB                                           usbprint.sys          6.1.7600.16385                        
    USBSTOR              USB                                  USBSTOR.SYS           6.1.7601.19144                        
    usbuhci            Microsoft USB  -         usbuhci.sys           6.1.7601.18328                        
    usbvideo         USB- (WDM)                                               usbvideo.sys          6.1.7601.18208                        
    vdrvroot             ()                   vdrvroot.sys          6.1.7600.16385                        
    vga              vga                                                                     vgapnp.sys            6.1.7600.16385                        
    VgaSave          VgaSave                                                                 vga.sys               6.1.7600.16385                        
    VGPU             VGPU                                                                    rdvgkmd.sys                                                 
    vhdmp            vhdmp                                                                   vhdmp.sys             6.1.7601.17514                        
    viaide           viaide                                                                  viaide.sys            6.0.6000.170                          
    vmbus            vmbus                                                                   vmbus.sys             6.1.7601.17514                        
    VMBusHID         VMBusHID                                                                VMBusHID.sys          6.1.7601.17514                        
    volmgr                                                             volmgr.sys            6.1.7601.17514                        
    volmgrx                                                        volmgrx.sys           6.1.7601.17514                        
    volsnap                                                         volsnap.sys           6.1.7601.17514                        
    vsmraid          vsmraid                                                                 vsmraid.sys           6.0.6000.6210                         
    vwifibus           Virtual WiFi                                               vwifibus.sys          6.1.7600.16385                        
    WacomPen         Wacom -                                wacompen.sys          6.1.7600.16385                        
    WANARP              IP ARP                                       wanarp.sys            6.1.7601.17514                        
    Wanarpv6            IPv6 ARP                                     wanarp.sys            6.1.7601.17514                        
    Wd               Wd                                                                      wd.sys                6.1.7600.16385                        
    Wdf01000                                                 Wdf01000.sys          1.11.9200.16648                       
    WfpLwf           WFP Lightweight Filter                                                  wfplwf.sys            6.1.7600.16385                        
    WIMMount         WIMMount                                                                wimmount.sys          6.1.7600.16385             
    WinUsb           WinUsb                                                                  WinUsb.sys            6.1.7601.17514                        
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           6.1.7600.16385                        
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           6.1.7600.16385                        
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            6.2.9200.16384                        
    WUDFRd           WUDFRd                                                                  WUDFRd.sys            6.2.9200.16384                        
    xhunter1         xhunter1                                                                xhunter1.sys                                                


--------[  ]------------------------------------------------------------------------------------------------------

    AdobeFlashPlayerUpdateSvc          Adobe Flash Player Update Service                                       FlashPlayerUpdateService.exe  32.0.0.371                     LocalSystem
    AeLookupSvc                                                              svchost.exe           6.1.7600.16385                       localSystem
    ALG                                                                             alg.exe               6.1.7600.16385                 NT AUTHORITY\LocalService
    AMD External Events Utility        AMD External Events Utility                                             atiesrxx.exe          26.20.15029.27016                LocalSystem
    amdacpusrsvc                       ACP User Service                                                        amdacpusrsvc.exe                                     LocalSystem
    AppIDSvc                                                                            svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    AppMgmt                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    aspnet_state                         ASP.NET                                                aspnet_state.exe      4.7.3062.0                     NT AUTHORITY\NetworkService
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           6.1.7600.16385                       LocalSystem
    AudioSrv                           Windows Audio                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    AUEPLauncher                       AMD User Experience Program Launcher                                    AUEPLauncher.exe      1.0.0.1                        LocalSystem
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           6.1.7600.16385                       LocalSystem
    BDESVC                                BitLocker                                      svchost.exe           6.1.7600.16385                       localSystem
    BEService                          BattlEye Service                                                        BEService.exe                                        LocalSystem
    BFE                                                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           6.1.7600.16385                       LocalSystem
    Browser                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    bthserv                              Bluetooth                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    CertPropSvc                                                                      svchost.exe           6.1.7600.16385                       LocalSystem
    clr_optimization_v2.0.50727_32     Microsoft .NET Framework NGEN v2.0.50727_X86                            mscorsvw.exe          2.0.50727.5483                 LocalSystem
    clr_optimization_v2.0.50727_64     Microsoft .NET Framework NGEN v2.0.50727_X64                            mscorsvw.exe          2.0.50727.5483                 LocalSystem
    clr_optimization_v4.0.30319_32     Microsoft .NET Framework NGEN v4.0.30319_X86                            mscorsvw.exe          4.7.3062.0                     LocalSystem
    clr_optimization_v4.0.30319_64     Microsoft .NET Framework NGEN v4.0.30319_X64                            mscorsvw.exe          4.7.3062.0                     LocalSystem
    COMSysApp                            COM+                                               dllhost.exe           6.1.7600.16385                 LocalSystem
    CryptSvc                                                                                 svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    CscService                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           6.1.7600.16385                       LocalSystem
    defragsvc                                                                               svchost.exe           6.1.7600.16385                 localSystem
    Dhcp                               DHCP-                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Dnscache                           DNS-                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    dot3svc                                                                              svchost.exe           6.1.7600.16385                       localSystem
    DPS                                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EapHost                                (EAP)                         svchost.exe           6.1.7600.16385                       localSystem
    EasyAntiCheat                      EasyAntiCheat                                                           EasyAntiCheat.exe                                    LocalSystem
    EFS                                   (EFS)                                      lsass.exe             6.1.7601.19160                       LocalSystem
    ehRecvr                              Windows Media Center                                    ehRecvr.exe           6.1.7601.17514                 NT AUTHORITY\networkService
    ehSched                              Windows Media Center                                ehsched.exe           6.1.7600.16385                 NT AUTHORITY\networkService
    eventlog                             Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Fax                                                                                                    fxssvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    fdPHost                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache                             Windows                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.5011                  NT Authority\LocalService
    gpsvc                                                                               svchost.exe           6.1.7600.16385                 LocalSystem
    hidserv                              HID-                                                svchost.exe           6.1.7600.16385                       LocalSystem
    hkmsvc                                                      svchost.exe           6.1.7600.16385                       localSystem
    HomeGroupListener                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    HomeGroupProvider                                                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    idsvc                              Windows CardSpace                                                       infocard.exe          3.0.4506.5464                        LocalSystem
    IEEtwCollectorService              Internet Explorer ETW Collector Service                                 IEEtwCollector.exe    11.0.9600.18231                LocalSystem
    IKEEXT                               IPsec        IP     svchost.exe           6.1.7600.16385                       LocalSystem
    IPBusEnum                           IP- PnP-X                                              svchost.exe           6.1.7600.16385                       LocalSystem
    iphlpsvc                             IP                                               svchost.exe           6.1.7600.16385                       LocalSystem
    KeyIso                               CNG                                                     lsass.exe             6.1.7601.19160                       LocalSystem
    KtmRm                              KtmRm                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    LanmanWorkstation                                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    lltdsvc                                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Mcx2Svc                              Media Center                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MMCSS                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    MpsSvc                              Windows                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MSDTC                                                                   msdtc.exe             2001.12.8530.16385                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           6.1.7600.16385                       LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.7601.18896                 LocalSystem
    napagent                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Netlogon                                                                                lsass.exe             6.1.7601.19160                       LocalSystem
    Netman                                                                                   svchost.exe           6.1.7600.16385                       LocalSystem
    NetMsmqActivator                     Net.Msmq                                         SMSvcHost.exe         4.7.3062.0                           NT AUTHORITY\NetworkService
    NetPipeActivator                     Net.Pipe                                         SMSvcHost.exe         4.7.3062.0                           NT AUTHORITY\LocalService
    netprofm                                                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    NetTcpActivator                      Net.Tcp                                          SMSvcHost.exe         4.7.3062.0                           NT AUTHORITY\LocalService
    NetTcpPortSharing                       Net.Tcp                                  SMSvcHost.exe         4.7.3062.0                           NT AUTHORITY\LocalService
    NlaSvc                                                                     svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    p2pimsvc                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    PerfHost                                                           perfhost.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    pla                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PlugPlay                           Plug-and-Play                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Power                                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    ProfSvc                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    ProtectedStorage                                                                        lsass.exe             6.1.7601.19160                       LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           6.1.7600.16385                       localSystem
    RasMan                                                                svchost.exe           6.1.7600.16385                       localSystem
    RemoteAccess                                                                  svchost.exe           6.1.7600.16385                       localSystem
    RemoteRegistry                                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Rockstar Service                   Rockstar Game Library Service                                           RockstarService.exe   1.0.23.252                     LocalSystem
    RpcEptMapper                          RPC                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           6.1.7600.16385                 NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    SaferVPN.Service                   SaferVPN.Service                                                        SaferVPN.Service.exe                                 LocalSystem
    SamSs                                                                   lsass.exe             6.1.7601.19160                       LocalSystem
    SCardSvr                           -                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Schedule                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    SCPolicySvc                          -                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SDRSVC                              Windows                                                       svchost.exe           6.1.7600.16385                 localSystem
    seclogon                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    SENS                                                                    svchost.exe           6.1.7600.16385                       LocalSystem
    SensrSvc                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           6.1.7600.16385                       localSystem
    SharedAccess                             (ICS)                            svchost.exe           6.1.7600.16385                       LocalSystem
    ShellHWDetection                                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SNMPTRAP                            SNMP                                                            snmptrap.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           6.1.7601.17514                 LocalSystem
    sppsvc                                                                        sppsvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    sppuinotify                          SPP                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SSDPSRV                             SSDP                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SstpSvc                             SSTP                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Steam Client Service               Steam Client Service                                                    SteamService.exe      5.90.98.72                     LocalSystem
    stisvc                                Windows (WIA)                               svchost.exe           6.1.7600.16385                 NT Authority\LocalService
    swprv                                  (Microsoft)                  svchost.exe           6.1.7600.16385                 LocalSystem
    SysMain                            Superfetch                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    TabletInputService                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TapiSrv                                                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    TBS                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TeamViewer                         TeamViewer                                                              TeamViewer_Service.exe  15.5.3.0                       LocalSystem
    TermService                                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    THREADORDER                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TrkWks                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  6.1.7601.17514                 localSystem
    UI0Detect                                                                     UI0Detect.exe         6.1.7600.16385                 LocalSystem
    UmRdpService                                svchost.exe           6.1.7600.16385                       localSystem
    uncheater_bgl                      Uncheater for BattleGroundsLite_SE                                      uncheater_bgl.exe     3.1.0.1                        LocalSystem
    upnphost                             PNP-                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    UxSms                                                           svchost.exe           6.1.7600.16385                       localSystem
    VaultSvc                                                                             lsass.exe             6.1.7601.19160                       LocalSystem
    vds                                                                                         vds.exe               6.1.7601.17514                 LocalSystem
    VSS                                                                                  vssvc.exe             6.1.7601.17514                 LocalSystem
    W32Time                              Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WatAdminSvc                           Windows                                     WatAdminSvc.exe       7.1.7600.16395                 LocalSystem
    wbengine                                                                wbengine.exe          6.1.7601.17514                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wcncsvc                              Windows -                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WcsPlugInService                     Windows (WCS)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WebClient                          -                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    wercplsupport                          "     "  svchost.exe           6.1.7600.16385                       localSystem
    WerSvc                                Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinDefend                           Windows                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Wlansvc                              WLAN                                               svchost.exe           6.1.7600.16385                       LocalSystem
    wmiApSrv                           WMI Performance Adapter                                                 WmiApSrv.exe          6.1.7600.16385                 localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe                                         NT AUTHORITY\NetworkService
    WPCSvc                             Parental Controls                                                       svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    WPDBusEnum                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wscsvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.7601.17610                 LocalSystem
    wuauserv                             Windows                                                svchost.exe           6.1.7600.16385                       LocalSystem
    wudfsvc                            Windows Driver Foundation - User-mode Driver Framework                  svchost.exe           6.1.7600.16385                       LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService


--------[  AX ]----------------------------------------------------------------------------------------------------

    bdaplgin.ax                6.1.7600.16385              Microsoft BDA Device Control Plug-in for MPEG2 based networks.
    g711codc.ax                6.1.7601.17514              Intel G711 CODEC
    iac25_32.ax                2.0.5.53                      Indeo audio
    ir41_32.ax                 4.51.16.3                   Intel Indeo Video 4.5
    ivfsrc.ax                  5.10.2.51                    Intel Indeo video IVF  5.10
    ksproxy.ax                 6.1.7601.19091              WDM Streaming ActiveMovie Proxy
    kstvtune.ax                6.1.7601.17514               - WDM
    kswdmcap.ax                6.1.7601.17514                WDM
    ksxbar.ax                  6.1.7601.17514              WDM Streaming Crossbar
    mpeg2data.ax               6.6.7601.17514              Microsoft MPEG-2 Section and Table Acquisition Module
    mpg2splt.ax                6.6.7601.17528              DirectShow MPEG-2 Splitter.
    msdvbnp.ax                 6.6.7601.17514              Microsoft Network Provider for MPEG2 based networks.
    msnp.ax                    6.6.7601.17514              Microsoft Network Provider for MPEG2 based networks.
    psisrndr.ax                6.6.7601.17669              Microsoft Transport Information Filter for MPEG2 based networks.
    vbicodec.ax                6.6.7601.17514              Microsoft VBI Codec
    vbisurf.ax                 6.1.7601.17514              VBI Surface Allocator Filter
    vidcap.ax                  6.1.7600.16385              Video Capture Interface Server
    wstpager.ax                6.6.7601.17514              Microsoft Teletext Server
    xvid.ax                                                


--------[  DLL ]---------------------------------------------------------------------------------------------------

    accessibilitycpl.dll       6.1.7601.17514                 
    acctres.dll                6.1.7600.16385                     (Microsoft)
    acledit.dll                6.1.7600.16385                 ACL
    aclui.dll                  6.1.7600.16385                
    acppage.dll                6.1.7601.17514                  ""
    actioncenter.dll           6.1.7601.17514               
    actioncentercpl.dll        6.1.7601.17514                 
    activeds.dll               6.1.7601.17514               DLL   AD
    actxprxy.dll               6.1.7601.17514              ActiveX Interface Marshaling Library
    admtmpl.dll                6.1.7601.17514               " "
    adprovider.dll             6.1.7601.18409               DLL adprovider
    adsldp.dll                 6.1.7601.17514              ADs LDAP Provider DLL
    adsldpc.dll                6.1.7600.16385               DLL  LDAP AD
    adsmsext.dll               6.1.7600.16385              ADs LDAP Provider DLL
    adsnt.dll                  6.1.7600.16385               DLL    Windows NT
    adtschema.dll              6.1.7601.19160                 
    advapi32.dll               6.1.7601.19160                API Windows 32
    advpack.dll                8.0.7600.16385              ADVPACK
    aecache.dll                6.1.7600.16385              AECache Sysprep Plugin
    aeevts.dll                 6.1.7600.16385                  
    alttab.dll                 6.1.7600.16385              Windows Shell Alt Tab
    amd_comgr32.dll                                        
    amdave32.dll               26.20.15029.27016           Radeon AMD AVE Driver Component
    amdgfxinfo32.dll                                       
    amdihk32.dll               2.0.0.1788                  Radeon Settings: Host Service
    amdlvr32.dll               1.0.16.0                    LiquidVR SDK 1.0
    amdmantle32.dll            26.20.15029.27016           Mantle driver, support for SI family and above
    amdmcl32.dll               1.6.0.0                     Radeon MCL Universal Driver
    amdmmcl.dll                26.20.15029.27016           Radeon MMOCL Universal Driver
    amdocl.dll                 10.0.3004.8                 AMD Accelerated Parallel Processing OpenCL 2.0 Runtime
    amdocl12cl.dll             0.8.0.0                     AMD COMPILER OpenCL 1.1 Compiler
    amdpcom32.dll              26.20.15029.27016           Radeon PCOM Universal Driver
    amduve32.dll               17.1.6.0                    Radeon AMD AVE Driver Component
    amdvlk32.dll               26.20.15029.27016           Vulkan driver, support for SI family and above
    amdxc32.dll                26.20.15029.27016           amdxc32.dll
    amdxn32.dll                8.14.10.53                  amdxn32.dll
    amfrt32.dll                1.4.16.0                    Advanced Media Framework
    amstream.dll               6.6.7601.17514              DirectShow Runtime.
    amxread.dll                6.1.7600.16385              API Tracing Manifest Read Library
    apds.dll                   6.1.7600.16385                  Microsoft
    apilogen.dll               6.1.7600.16385                 API
    api-ms-win-core-console-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-file-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-file-l1-2-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-core-file-l2-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-core-handle-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-heap-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-localization-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-localization-l1-2-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-core-localregistry-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-misc-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-1.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-core-profile-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-string-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-synch-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-synch-l1-2-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-timezone-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-core-util-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-core-xstate-l2-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-conio-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-convert-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-environment-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-filesystem-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-heap-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-locale-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-math-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-multibyte-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-private-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-process-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-runtime-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-stdio-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-string-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-time-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-crt-utility-l1-1-0.dll  10.0.10586.9                ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l2-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-normaliz-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-ole32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shell32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l2-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-user32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-version-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-security-base-l1-1-0.dll  6.1.7601.19160              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-sddl-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l2-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    apircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    apisetschema.dll           6.1.7601.19160              ApiSet Schema DLL
    apphelp.dll                6.1.7601.19050                 
    apphlpdm.dll               6.1.7600.16385                 
    appidapi.dll               6.1.7601.19021               API-  
    appidpolicyengineapi.dll   6.1.7600.16385              AppId Policy Engine API Module
    appmgmts.dll               6.1.7600.16385                
    appmgr.dll                 6.1.7601.17514                 
    apss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    asferror.dll               12.0.7600.16385               ASF
    aspnet_counters.dll        4.7.3062.0                  Microsoft ASP.NET Performance Counter Shim DLL
    asycfilt.dll               6.1.7601.19144              
    atiadlxx.dll               26.20.15029.27016           ADL
    atiadlxy.dll               26.20.15029.27016           ADL
    aticfx32.dll               26.20.15029.27016           aticfx32.dll
    atidxx32.dll               26.20.15029.27016           atidxx32.dll
    atigktxx.dll               26.20.15029.27016           atigktxx.dll
    atiglpxx.dll               26.20.15029.27016           atiglpxx.dll
    atimpc32.dll               26.20.15029.27016           Radeon PCOM Universal Driver
    atioglxx.dll               26.20.15029.27016           AMD OpenGL driver
    atisamu32.dll              26.20.15029.27016           Radeon spu api dll
    atiu9pag.dll               26.20.15029.27016           atiu9pag.dll
    atiumdag.dll               26.20.15029.27016           atiumdag.dll
    atiumdva.dll               26.20.15029.27016           Radeon Video Acceleration Universal Driver
    atiuxpag.dll               26.20.15029.27016           atiuxpag.dll
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atl100.dll                 10.0.40219.325              ATL Module for Windows
    atl110.dll                 11.0.60610.1                ATL Module for Windows
    atl70.dll                  7.0.9975.0                  ATL Module for Windows (Unicode)
    atl71.dll                  7.10.6101.0                 ATL Module for Windows (Unicode)
    atmfd.dll                  5.1.2.247                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.247                   Windows NT OpenType/Type 1 API Library.
    atrc.dll                   17.0.6.13                   Sony ATRAC3 Audio Codec for RealAudio 8(tm)
    audiodev.dll               6.1.7601.17514                   
    audioeng.dll               6.1.7601.18741              Audio Engine
    audiokse.dll               6.1.7601.18741              Audio Ks Endpoint
    audioses.dll               6.1.7601.18741                
    auditnativesnapin.dll      6.1.7600.16385                    
    auditpolicygpinterop.dll   6.1.7600.16385                 
    auditpolmsg.dll            6.1.7600.16385                MMC  
    authfwcfg.dll              6.1.7600.16385               Windows      
    authfwgp.dll               6.1.7600.16385               Windows c      
    authfwsnapin.dll           6.1.7601.17514              Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           6.1.7600.16385              Wizard Framework
    authui.dll                 6.1.7601.18896                
    authz.dll                  6.1.7600.16385              Authorization Framework
    autoplay.dll               6.1.7601.17514               ( )
    auxiliarydisplayapi.dll    6.1.7600.16385              Microsoft Windows SideShow API
    auxiliarydisplaycpl.dll    6.1.7601.17514                Microsoft Windows SideShow
    avicap32.dll               6.1.7600.16385                 AVI
    avifil32.dll               6.1.7601.17514                 AVI
    avrt.dll                   6.1.7600.16385              Multimedia Realtime Runtime
    azroles.dll                6.1.7601.17514              azroles Module
    azroleui.dll               6.1.7601.17514               
    azsqlext.dll               6.1.7601.17514              AzMan Sql Audit Extended Stored Procedures Dll
    basecsp.dll                6.1.7601.17514                 - (Microsoft)
    batmeter.dll               6.1.7601.17514              Battery Meter Helper DLL
    bcrypt.dll                 6.1.7600.16385              Windows Cryptographic Primitives Library (Wow64)
    bcryptprimitives.dll       6.1.7601.19012              Windows Cryptographic Primitives Library
    bidispl.dll                6.1.7600.16385              Bidispl DLL
    binkw32.dll                1.5.21.0                    RAD Video Tools
    biocredprov.dll            6.1.7600.16385                 WinBio
    bitsperf.dll               7.5.7601.17514              Perfmon Counter Access
    bitsprx2.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    bitsprx3.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.0 Proxy
    bitsprx4.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.5 Proxy
    bitsprx5.dll               7.5.7600.16385              Background Intelligent Transfer Service 3.0 Proxy
    bitsprx6.dll               7.5.7600.16385              Background Intelligent Transfer Service 4.0 Proxy
    blackbox.dll               11.0.7601.18741             BlackBox DLL
    bootvid.dll                6.1.7600.16385              VGA Boot Driver
    browcli.dll                6.1.7601.17887              Browser Service Client DLL
    browseui.dll               6.1.7601.17514              Shell Browser UI Library
    btpanui.dll                6.1.7600.16385                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    bwunpairelevated.dll       6.1.7600.16385              BWUnpairElevated Proxy Dll
    c_g18030.dll               6.1.7600.16385              GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               6.1.7600.16385              ISO-2022 Code Page Translation DLL
    c_iscii.dll                6.1.7601.17514              ISCII Code Page Translation DLL
    cabinet.dll                6.1.7601.17514              Microsoft Cabinet File API
    cabview.dll                6.1.7601.17514                 CAB-
    camcodec.dll               1.5.0.0                     CamStudio Lossless Video Codec
    capiprovider.dll           6.1.7601.18409               DLL capiprovider
    capisp.dll                 6.1.7600.16385              Sysprep cleanup dll for CAPI
    catsrv.dll                 2001.12.8530.16385          COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.8531.19062          COM+ Configuration Catalog Server Utilities
    cca.dll                    6.6.7601.17514              CCA DirectShow Filter.
    cdosys.dll                 6.6.7601.17857              Microsoft CDO for Windows Library
    certcli.dll                6.1.7601.18833                 Microsoft Active Directory
    certcredprovider.dll       6.1.7600.16385                 
    certenc.dll                6.1.7601.18151              Active Directory Certificate Services Encoding
    certenroll.dll             6.1.7601.17514                  Active Directory Microsoft
    certenrollui.dll           6.1.7600.16385                  X509
    certmgr.dll                6.1.7601.17514                
    certpoleng.dll             6.1.7601.17514                
    cewmdm.dll                 12.0.7601.18872               Windows CE WMDM
    cfgbkend.dll               6.1.7600.16385              Configuration Backend Interface
    cfgmgr32.dll               6.1.7601.17621              Configuration Manager DLL
    cfhd.dll                   3.2.2.185                   CineForm VFW CODEC
    chsbrkr.dll                6.1.7600.16385              Simplified Chinese Word Breaker
    chtbrkr.dll                6.1.7600.16385              Chinese Traditional Word Breaker
    chxreadingstringime.dll    6.1.7600.16385              CHxReadingStringIME
    cic.dll                    6.1.7600.16385                CIC - MMC   
    clb.dll                    6.1.7600.16385                
    clbcatq.dll                2001.12.8530.16385          COM+ Configuration Catalog
    clfsw32.dll                6.1.7601.18777              Common Log Marshalling Win32 DLL
    cliconfg.dll               6.1.7600.16385              SQL Client Configuration Utility DLL
    clusapi.dll                6.1.7601.17514               API 
    cmcfg32.dll                7.2.7600.16385                  Microsoft
    cmdial32.dll               7.2.7600.16385               
    cmicryptinstall.dll        6.1.7600.16385              Installers for cryptographic elements of CMI objects
    cmifw.dll                  6.1.7600.16385              Windows Firewall rule configuration plug-in
    cmipnpinstall.dll          6.1.7600.16385              PNP plugin installer for CMI
    cmlua.dll                  7.2.7600.16385                API   
    cmpbk32.dll                7.2.7600.16385              Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.7600.16385                API      
    cmutil.dll                 7.2.7600.16385                  (Microsoft)
    cngaudit.dll               6.1.7600.16385              Windows Cryptographic Next Generation audit library
    cngprovider.dll            6.1.7601.18409               DLL cngprovider
    cnvfat.dll                 6.1.7600.16385              FAT File System Conversion Utility DLL
    colbact.dll                2001.12.8530.16385          COM+
    colorcnv.dll               6.1.7601.19091              Windows Media Color Conversion
    colorui.dll                6.1.7600.16385                 
    comcat.dll                 6.1.7600.16385              Microsoft Component Category Manager Library
    comctl32.dll               5.82.7601.18837                  
    comdlg32.dll               6.1.7601.17514                 
    compobj.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    compstui.dll               6.1.7600.16385                   
    comrepl.dll                2001.12.8530.16385          COM+
    comres.dll                 2001.12.8530.16385           COM+
    comsnap.dll                2001.12.8530.16385          COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.8531.19062          COM+ Services
    comuid.dll                 2001.12.8530.16385          COM+ Explorer UI
    concrt140.dll              14.23.27820.0               Microsoft Concurrency Runtime Library
    connect.dll                6.1.7600.16385               
    console.dll                6.1.7600.16385                 
    cook.dll                   17.0.6.13                   Cooker G2 Audio Codec for RealAudio(tm)
    cpfilters.dll              6.6.7601.19135               PTFilter & Encypter/Decrypter Tagger Filters.
    credssp.dll                6.1.7601.19160              Credential Delegation Security Package
    credui.dll                 6.1.7601.18276                 
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                6.1.7601.18839              API32 
    cryptbase.dll              6.1.7601.19160              Base cryptographic API DLL
    cryptdlg.dll               6.1.7601.18150                
    cryptdll.dll               6.1.7600.16385              Cryptography Manager
    cryptext.dll               6.1.7600.16385                
    cryptnet.dll               6.1.7601.18839              Crypto Network Related API
    cryptsp.dll                6.1.7601.18741              Cryptographic Service Provider API
    cryptsvc.dll               6.1.7601.18839               
    cryptui.dll                6.1.7601.18741                
    cryptxml.dll               6.1.7600.16385              API- XML DigSig
    cscapi.dll                 6.1.7601.17514              Offline Files Win32 API
    cscdll.dll                 6.1.7601.17514              Offline Files Temporary Shim
    cscobj.dll                 6.1.7601.17514               COM-   CSC API
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    d2d1.dll                   6.2.9200.16765               Microsoft D2D
    d3d10.dll                  6.2.9200.16492              Direct3D 10 Runtime
    d3d10_1.dll                6.2.9200.16492              Direct3D 10.1 Runtime
    d3d10_1core.dll            6.2.9200.16492              Direct3D 10.1 Runtime
    d3d10core.dll              6.2.9200.16492              Direct3D 10 Runtime
    d3d10level9.dll            6.2.9200.16492              Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              6.2.9200.17033              Direct3D 10 Rasterizer
    d3d11.dll                  6.2.9200.16570              Direct3D 11 Runtime
    d3d8.dll                   6.1.7600.16385              Microsoft Direct3D
    d3d8thk.dll                6.1.7600.16385              Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   6.1.7601.17514              Direct3D 9 Runtime
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcompiler_47.dll         10.0.10240.16384            Direct3D HLSL Compiler for Redistribution
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  6.1.7600.16385              Microsoft Direct3D
    d3dim700.dll               6.1.7600.16385              Microsoft Direct3D
    d3dramp.dll                6.1.7600.16385              Microsoft Direct3D
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 6.1.7600.16385              DirectX Files DLL
    dataclen.dll               6.1.7600.16385                 Windows
    davclnt.dll                6.1.7601.18912              Web DAV Client DLL
    davhlpr.dll                6.1.7600.16385              DAV Helper DLL
    dbgeng.dll                 6.1.7601.17514              Windows Symbolic Debugger Engine
    dbghelp.dll                6.1.7601.17514              Windows Image Helper
    dbnetlib.dll               6.1.7600.16385              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               6.1.7600.16385              Named Pipes Net DLL for SQL Clients
    dciman32.dll               6.1.7601.19146              DCI Manager
    ddaclsys.dll               6.1.7600.16385              SysPrep module for Reseting Data Drive ACL 
    ddoiproxy.dll              6.1.7600.16385              DDOI Interface Proxy
    ddores.dll                 6.1.7600.16385                  
    ddraw.dll                  6.1.7600.16385              Microsoft DirectDraw
    ddrawex.dll                6.1.7600.16385              Direct Draw Ex
    defaultlocationcpl.dll     6.1.7601.17514               :   
    deskadp.dll                6.1.7600.16385                 
    deskmon.dll                6.1.7600.16385                
    deskperf.dll               6.1.7600.16385                
    detoured.dll               26.20.15029.27016           Marks process modified by Detours technology.
    devenum.dll                6.6.7601.19091               .
    devicecenter.dll           6.1.7601.17514                
    devicedisplaystatusmanager.dll  6.1.7600.16385              Device Display Status Manager
    devicemetadataparsers.dll  6.1.7600.16385              Common Device Metadata parsers
    devicepairing.dll          6.1.7600.16385               ,   
    devicepairingfolder.dll    6.1.7601.17514                 
    devicepairinghandler.dll   6.1.7600.16385              Device Pairing Handler Dll
    devicepairingproxy.dll     6.1.7600.16385              Device Pairing Proxy Dll
    deviceuxres.dll            6.1.7600.16385              Windows Device User Experience Resource File
    devmgr.dll                 6.1.7600.16385                 
    devobj.dll                 6.1.7601.17621              Device Information Set DLL
    devrtl.dll                 6.1.7601.17621              Device Management Run Time Library
    dfscli.dll                 6.1.7600.16385              Windows NT Distributed File System Client DLL
    dfshim.dll                 4.0.41210.0                     ClickOnce
    dfsshlex.dll               6.1.7600.16385                   DFS
    dhcpcmonitor.dll           6.1.7600.16385               (DLL)   DHCP
    dhcpcore.dll               6.1.7601.17514               DHCP-
    dhcpcore6.dll              6.1.7601.17970               DHCPv6
    dhcpcsvc.dll               6.1.7600.16385               DHCP-
    dhcpcsvc6.dll              6.1.7601.17970               DHCPv6
    dhcpqec.dll                6.1.7600.16385                   Microsoft DHCP
    dhcpsapi.dll               6.1.7600.16385               API  DHCP-c
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                6.1.7600.16385               DLL  DIMS
    dimsroam.dll               6.1.7601.18409               DLL  DIMS  
    dinput.dll                 6.1.7600.16385              Microsoft DirectInput
    dinput8.dll                6.1.7600.16385              Microsoft DirectInput
    directdb.dll               6.1.7600.16385              Microsoft Direct Database API
    directdb.dll               6.1.7600.16385              Microsoft Direct Database API
    diskcopy.dll               6.1.7600.16385              Windows DiskCopy
    dispex.dll                 5.8.7600.16385              Microsoft  DispEx
    display.dll                6.1.7601.17514                
    dmband.dll                 6.1.7600.16385              Microsoft DirectMusic Band
    dmcompos.dll               6.1.7600.16385              Microsoft DirectMusic Composer
    dmdlgs.dll                 6.1.7600.16385              Disk Management Snap-in Dialogs
    dmdskmgr.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dmdskres.dll               6.1.7600.16385                 
    dmdskres2.dll              6.1.7600.16385                 
    dmime.dll                  6.1.7600.16385              Microsoft DirectMusic Interactive Engine
    dmintf.dll                 6.1.7600.16385              Disk Management DCOM Interface Stub
    dmloader.dll               6.1.7600.16385              Microsoft DirectMusic Loader
    dmocx.dll                  6.1.7600.16385              TreeView OCX
    dmrc.dll                   6.1.7600.16385              Windows MRC
    dmscript.dll               6.1.7600.16385              Microsoft DirectMusic Scripting
    dmstyle.dll                6.1.7600.16385              Microsoft DirectMusic Style Engline
    dmsynth.dll                6.1.7600.16385              Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 6.1.7600.16385                Microsoft DirectMusic
    dmutil.dll                 6.1.7600.16385                 
    dmvdsitf.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dnet.dll                   6.0.7.5189                  DolbyNet(tm) Audio Codec for RealAudio(tm)
    dnsapi.dll                 6.1.7601.17570                API DNS-
    dnscmmc.dll                6.1.7601.17514               DLL  DNS  MMC
    docprop.dll                6.1.7600.16385                OLE
    dot3api.dll                6.1.7601.17514              802.3 Autoconfiguration API
    dot3cfg.dll                6.1.7601.17514               Netsh  802.3
    dot3dlg.dll                6.1.7600.16385                UI  802.3
    dot3gpclnt.dll             6.1.7600.16385                   802.3
    dot3gpui.dll               6.1.7600.16385               "   802.3"
    dot3hc.dll                 6.1.7600.16385                 Dot3
    dot3msm.dll                6.1.7601.17514                   802.3
    dot3ui.dll                 6.1.7601.17514                802.3
    dpapiprovider.dll          6.1.7601.18409               DLL dpapiprovider
    dplayx.dll                 6.1.7600.16385              Microsoft DirectPlay
    dpmodemx.dll               6.1.7600.16385                      DirectPlay
    dpnaddr.dll                6.1.7601.17514              Microsoft DirectPlay8 Address
    dpnathlp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPnP
    dpnet.dll                  6.1.7601.17989              Microsoft DirectPlay
    dpnhpast.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPNP
    dpnlobby.dll               6.1.7600.16385              Microsoft DirectPlay8 Lobby
    dpwsockx.dll               6.1.7600.16385                  TCP/IP  IPX  DirectPlay
    dpx.dll                    6.1.7601.17514              Microsoft(R) Delta Package Expander
    drmmgrtn.dll               11.0.7601.18741             DRM Migration DLL
    drmv2clt.dll               11.0.7601.18741             DRMv2 Client DLL
    drprov.dll                 6.1.7600.16385                   ,        ()
    drt.dll                    6.1.7600.16385                
    drtprov.dll                6.1.7600.16385              Distributed Routing Table Providers
    drttransport.dll           6.1.7600.16385              Distributed Routing Table Transport Provider
    drv1.dll                   17.0.6.13                   RealVideo 1.0
    drv2.dll                   17.0.6.13                   RealVideo G2
    drvc.dll                   17.0.6.13                   RealVideo 8+9
    drvstore.dll               6.1.7601.17514              Driver Store API
    ds32gt.dll                 6.1.7600.16385              ODBC Driver Setup Generic Thunk
    dsauth.dll                 6.1.7601.17514              DS Authorization for Services
    dsdmo.dll                  6.1.7600.16385              DirectSound Effects
    dshowrdpfilter.dll         1.0.0.0                           ()
    dskquota.dll               6.1.7600.16385               DLL    Windows
    dskquoui.dll               6.1.7601.17514               DLL   
    dsound.dll                 6.1.7600.16385              DirectSound
    dsprop.dll                 6.1.7600.16385                Active Directory
    dsquery.dll                6.1.7600.16385                 
    dsrole.dll                 6.1.7600.16385              DS Role Client DLL
    dssec.dll                  6.1.7600.16385                 
    dssenh.dll                 6.1.7600.16385              Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsuiext.dll                6.1.7601.17514                 
    dswave.dll                 6.1.7600.16385              Microsoft DirectMusic Wave
    dtsh.dll                   6.1.7600.16385               API     
    dui70.dll                  6.1.7600.16385               DirectUI Windows
    duser.dll                  6.1.7600.16385              Windows DirectUser Engine
    dwmapi.dll                 6.1.7601.18917               API     ()
    dwmcore.dll                6.1.7601.18917                Microsoft DWM
    dwrite.dll                 6.2.9200.17568               Microsoft DirectX Typography
    dxdiagn.dll                6.1.7601.17514                Microsoft DirectX
    dxgi.dll                   6.2.9200.16492              DirectX Graphics Infrastructure
    dxmasf.dll                 12.0.7601.19148             Microsoft Windows Media Component Removal File.
    dxptaskringtone.dll        6.1.7601.17514                 Microsoft
    dxptasksync.dll            6.1.7601.17514               Microsoft Windows DXP
    dxtmsft.dll                11.0.9600.18231             DirectX Media -- Image DirectX Transforms
    dxtrans.dll                11.0.9600.18231             DirectX Media -- DirectX Transform Core
    dxva2.dll                  6.1.7600.16385              DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               6.1.7601.17514              Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                6.1.7600.16385                EAP
    eappgnui.dll               6.1.7601.17514                 EAP
    eapphost.dll               6.1.7601.17514                 EAPHost 
    eappprxy.dll               6.1.7600.16385              Microsoft EAPHost Peer Client DLL
    eapqec.dll                 6.1.7600.16385                   Microsoft EAP
    efsadu.dll                 6.1.7600.16385                
    efscore.dll                6.1.7601.17514              EFS Core Library
    efsutil.dll                6.1.7600.16385              EFS Utility Library
    ehstorapi.dll              6.1.7601.17514              Windows Enhanced Storage API
    ehstorpwdmgr.dll           6.1.7600.16385                Windows Enhanced Storage
    ehstorshell.dll            6.1.7600.16385               DLL   Windows Enhanced Storage
    els.dll                    6.1.7601.19054                
    elscore.dll                6.1.7600.16385               DLL   Els
    elshyph.dll                6.3.9600.16428              ELS Hyphenation Service
    elslad.dll                 6.1.7600.16385              ELS Language Detection
    elstrans.dll               6.1.7601.17514              ELS Transliteration Service
    encapi.dll                 6.1.7600.16385              Encoder API
    encdec.dll                 6.6.7601.19135                XDS     .
    eqossnap.dll               6.1.7600.16385                EQoS
    es.dll                     2001.12.8530.16385          COM+
    esent.dll                  6.1.7601.17577                  ESE  Microsoft(R) Windows(R)
    esentprf.dll               6.1.7600.16385              Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    eventcls.dll               6.1.7600.16385              Microsoft Volume Shadow Copy Service event class
    evr.dll                    6.1.7601.19091                DLL   
    explorerframe.dll          6.1.7601.18952              ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    f3ahvoas.dll               6.1.7600.16385              JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               6.1.7601.17514                     Windows
    fdbth.dll                  6.1.7600.16385              Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             6.1.7600.16385              Bluetooth Provider Proxy Dll
    fde.dll                    6.1.7601.17514                 
    fdeploy.dll                6.1.7601.17514                  
    fdpnp.dll                  6.1.7600.16385              Pnp Provider Dll
    fdproxy.dll                6.1.7600.16385              Function Discovery Proxy Dll
    fdssdp.dll                 6.1.7600.16385              Function Discovery SSDP Provider Dll
    fdwcn.dll                  6.1.7600.16385              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 6.1.7600.16385              Function Discovery WNet Provider Dll
    fdwsd.dll                  6.1.7600.16385              Function Discovery WS Discovery Provider Dll
    feclient.dll               6.1.7600.16385              Windows NT File Encryption Client Interfaces
    ff_vfw.dll                 1.3.4530.0                  ffdshow VFW
    filemgmt.dll               6.1.7600.16385                 
    findnetprinters.dll        6.1.7600.16385              Find Network Printers COM Component
    firewallapi.dll            6.1.7600.16385              API  Windows
    firewallcontrolpanel.dll   6.1.7601.17514                -  Windows
    fltlib.dll                 6.1.7600.16385               
    fmifs.dll                  6.1.7600.16385              FM IFS Utility DLL
    fms.dll                    1.1.6000.16384                
    fontext.dll                6.1.7601.17514                Windows
    fontsub.dll                6.1.7601.19146              Font Subsetting DLL
    fphc.dll                   6.1.7601.17514               Filtering Platform Helper
    framedyn.dll               6.1.7601.17514              WMI SDK Provider Framework
    framedynos.dll             6.1.7601.17514              WMI SDK Provider Framework
    fthsvc.dll                 6.1.7600.16385                  Microsoft Windows
    fundisc.dll                6.1.7600.16385              DLL  
    fwcfg.dll                  6.1.7600.16385                  Windows
    fwpuclnt.dll               6.1.7601.18283              API   FWP/IPsec
    fwremotesvr.dll            6.1.7600.16385              Windows Firewall Remote APIs Server
    fxsapi.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    fxscom.dll                 6.1.7600.16385              Microsoft Fax Server COM Client Interface
    fxscomex.dll               6.1.7600.16385              Microsoft Fax Server Extended COM Client Interface
    fxsext32.dll               6.1.7600.16385              Microsoft  Fax Exchange Command Extension
    fxsresm.dll                6.1.7600.16385               DLL   (Microsoft)
    fxsxp32.dll                6.1.7600.16385              Microsoft  Fax Transport Provider
    gamemanager32.dll                                      
    gameux.dll                 6.1.7601.18020               
    gameuxlegacygdfs.dll       1.0.0.1                     Legacy GDF resource DLL
    gameuxlegacygdfs_old.dll   1.0.0.1                     Legacy GDF resource DLL
    gcdef.dll                  6.1.7600.16385                   
    gdi32.dll                  6.1.7601.19091              GDI Client DLL
    geocodec.dll               8.4.0.0                     GeoVision(R) Codec
    geocodec_readonly.dll      8.4.0.0                     GeoVision(R) Codec
    geocodecd.dll              8.4.0.0                     GeoVision(R) Codec
    getuname.dll               6.1.7600.16385                   UCE
    glmf32.dll                 6.1.7600.16385              OpenGL Metafiling DLL
    glu32.dll                  6.1.7600.16385                OpenGL
    gpapi.dll                  6.1.7600.16385                API  
    gpedit.dll                 6.1.7600.16385              GPEdit
    gpprefcl.dll               6.1.7601.17514                 
    gpprnext.dll               6.1.7600.16385                 
    gpscript.dll               6.1.7600.16385                
    gptext.dll                 6.1.7600.16385              GPTExt
    hbaapi.dll                 6.1.7601.17514              HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            6.1.7600.16385                
    helppaneproxy.dll          6.1.7600.16385              Microsoft Help Proxy
    hgcpl.dll                  6.1.7601.17514                 
    hhsetup.dll                6.1.7600.16385              Microsoft HTML Help
    hid.dll                    6.1.7600.16385                HID
    hidserv.dll                6.1.7600.16385               HID
    hlink.dll                  6.1.7600.16385               Microsoft Office 2000
    hnetcfg.dll                6.1.7600.16385                 
    hnetmon.dll                6.1.7600.16385              DLL   
    httpapi.dll                6.1.7601.17514              HTTP Protocol Stack API
    htui.dll                   6.1.7600.16385                  
    ias.dll                    6.1.7600.16385                 (NPS)
    iasacct.dll                6.1.7601.17514                NPS
    iasads.dll                 6.1.7600.16385                Active Directory NPS
    iasdatastore.dll           6.1.7600.16385              NPS Datastore server
    iashlpr.dll                6.1.7600.16385                NPS
    iasmigplugin.dll           6.1.7600.16385              NPS Migration DLL
    iasnap.dll                 6.1.7600.16385              NPS NAP Provider
    iaspolcy.dll               6.1.7600.16385              NPS Pipeline
    iasrad.dll                 6.1.7601.17514                RADIUS NPS
    iasrecst.dll               6.1.7601.17514              NPS XML Datastore Access
    iassam.dll                 6.1.7600.16385              NPS NT SAM Provider
    iassdo.dll                 6.1.7600.16385               SDO NPS
    iassvcs.dll                6.1.7600.16385                NPS
    icardie.dll                11.0.9600.16428             Microsoft Information Card IE Helper
    icardres.dll               3.0.4506.5464               Windows CardSpace
    iccvid.dll                 1.10.0.13                    Cinepak
    icm32.dll                  6.1.7600.16385              Microsoft Color Management Module (CMM)
    icmp.dll                   6.1.7600.16385              ICMP DLL
    icmui.dll                  6.1.7600.16385                  
    iconcodecservice.dll       6.1.7600.16385              Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 6.1.7600.16385                 
    idndl.dll                  6.1.7600.16385              Downlevel DLL
    idstore.dll                6.1.7600.16385              Identity Store
    ieadvpack.dll              11.0.9600.16428             ADVPACK
    ieapfltr.dll               11.0.9600.18231             Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.9600.18231               IEAK
    ieetwproxystub.dll         11.0.9600.18231             IE ETW Collector Proxy Stub Resources
    ieframe.dll                11.0.9600.18231             
    iepeers.dll                11.0.9600.16428             Peer- Internet Explorer
    iernonce.dll               11.0.9600.18231               RunOnce   
    iertutil.dll               11.0.9600.18231             Run time utility for Internet Explorer
    iesetup.dll                11.0.9600.18231               IOD
    iesysprep.dll              11.0.9600.16428             IE Sysprep Provider
    ieui.dll                   11.0.9600.18231                Internet Explorer
    ifmon.dll                  6.1.7600.16385                IF
    ifsutil.dll                6.1.7601.17514              IFS Utility DLL
    ifsutilx.dll               6.1.7600.16385              IFS Utility Extension DLL
    imagehlp.dll               6.1.7601.18288              Windows NT Image Helper
    imageres.dll               6.1.7600.16385              Windows Image Resource
    imagesp1.dll               6.1.7600.16385              Windows SP1 Image Resource
    imapi.dll                  6.1.7600.16385               Image Mastering API
    imapi2.dll                 6.1.7601.17514              IMAPI  2
    imapi2fs.dll               6.1.7601.17514              Image Mastering File System Imaging API v2
    imgutil.dll                11.0.9600.16428             IE plugin image decoder support DLL
    imjp10k.dll                10.1.7601.18556             Microsoft IME
    imm32.dll                  6.1.7601.17514              Multi-User Windows IMM32 API Client DLL
    inetcomm.dll               6.1.7601.17609              Microsoft Internet Messaging API Resources
    inetmib1.dll               6.1.7601.17514              Microsoft MIB-II subagent
    inetres.dll                6.1.7600.16385               API  
    infocardapi.dll            3.0.4506.5461               Microsoft InfoCards
    inked.dll                  6.1.7601.19112              Microsoft Tablet PC InkEdit Control
    input.dll                  6.1.7601.17514               DLL  
    inseng.dll                 11.0.9600.18231              
    iologmsg.dll               6.1.7601.18386                /
    ipbusenumproxy.dll         6.1.7600.16385              Associated Device Presence Proxy Dll
    iphlpapi.dll               6.1.7601.17514              IP Helper API
    iprop.dll                  6.1.7600.16385              OLE PropertySet Implementation
    iprtprio.dll               6.1.7600.16385              IP Routing Protocol Priority DLL
    iprtrmgr.dll               6.1.7601.17514               IP-
    ipsecsnp.dll               6.1.7600.16385                 IP-
    ipsmsnap.dll               6.1.7601.17514                IP-
    ir32_32.dll                3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_32.dll                4.11.15.94                  Intel Indeo(R) Video Interactive 32-bit Driver
    ir41_qc.dll                4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    irclass.dll                6.1.7600.16385                 
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               6.1.7600.16385              API-  iSCSI
    iscsied.dll                6.1.7600.16385              iSCSI Extension DLL
    iscsium.dll                6.1.7601.17514              iSCSI Discovery api
    iscsiwmi.dll               6.1.7600.16385              MS iSCSI Initiator WMI Provider
    itircl.dll                 6.1.7601.17514              Microsoft InfoTech IR Local DLL
    itss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    itvdata.dll                6.6.7601.17514              iTV Data Filters.
    iyuv_32.dll                6.1.7601.17514              Intel Indeo(R) Video YUV 
    javascriptcollectionagent.dll  11.0.9600.18231             JavaScript Performance Collection Agent
    jscript.dll                5.8.9600.18231              Microsoft  JScript
    jscript9.dll               11.0.9600.18231             Microsoft  JScript
    jscript9diag.dll           11.0.9600.18231             Microsoft  JScript Diagnostics
    jsintl.dll                 6.3.9600.16428              Windows Globalization
    jsproxy.dll                11.0.9600.18231             JScript Proxy Auto-Configuration
    kbd101.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 101
    kbd101a.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout for 103
    kbd106.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbd106n.dll                6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbda1.dll                  6.1.7600.16385              Arabic_English_101 Keyboard Layout
    kbda2.dll                  6.1.7600.16385              Arabic_2 Keyboard Layout
    kbda3.dll                  6.1.7600.16385              Arabic_French_102 Keyboard Layout
    kbdal.dll                  6.1.7600.16385              Albania Keyboard Layout
    kbdarme.dll                6.1.7600.16385              Eastern Armenian Keyboard Layout
    kbdarmw.dll                6.1.7600.16385              Western Armenian Keyboard Layout
    kbdax2.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 6.1.7601.19106              Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                6.1.7601.19106              Azeri-Latin Keyboard Layout
    kbdbash.dll                6.1.7601.18528              Bashkir Keyboard Layout
    kbdbe.dll                  6.1.7600.16385              Belgian Keyboard Layout
    kbdbene.dll                6.1.7600.16385              Belgian Dutch Keyboard Layout
    kbdbgph.dll                6.1.7600.16385              Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               6.1.7600.16385              Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 6.1.7600.16385              Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 6.1.7601.17514              Belarusian Keyboard Layout
    kbdbr.dll                  6.1.7600.16385              Brazilian Keyboard Layout
    kbdbu.dll                  6.1.7600.16385              Bulgarian (Typewriter) Keyboard Layout
    kbdbulg.dll                6.1.7601.17514              Bulgarian Keyboard Layout
    kbdca.dll                  6.1.7600.16385              Canadian Multilingual Keyboard Layout
    kbdcan.dll                 6.1.7600.16385              Canadian Multilingual Standard Keyboard Layout
    kbdcr.dll                  6.1.7600.16385              Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  6.1.7600.16385              Czech Keyboard Layout
    kbdcz1.dll                 6.1.7601.17514              Czech_101 Keyboard Layout
    kbdcz2.dll                 6.1.7600.16385              Czech_Programmer's Keyboard Layout
    kbdda.dll                  6.1.7600.16385              Danish Keyboard Layout
    kbddiv1.dll                6.1.7600.16385              Divehi Phonetic Keyboard Layout
    kbddiv2.dll                6.1.7600.16385              Divehi Typewriter Keyboard Layout
    kbddv.dll                  6.1.7600.16385              Dvorak US English Keyboard Layout
    kbdes.dll                  6.1.7600.16385              Spanish Alernate Keyboard Layout
    kbdest.dll                 6.1.7600.16385              Estonia Keyboard Layout
    kbdfa.dll                  6.1.7600.16385              Persian Keyboard Layout
    kbdfc.dll                  6.1.7600.16385              Canadian French Keyboard Layout
    kbdfi.dll                  6.1.7600.16385              Finnish Keyboard Layout
    kbdfi1.dll                 6.1.7600.16385              Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  6.1.7600.16385              F?roese Keyboard Layout
    kbdfr.dll                  6.1.7600.16385              French Keyboard Layout
    kbdgae.dll                 6.1.7600.16385              Gaelic Keyboard Layout
    kbdgeo.dll                 6.1.7601.17514              Georgian Keyboard Layout
    kbdgeoer.dll               6.1.7600.16385              Georgian (Ergonomic) Keyboard Layout
    kbdgeoqw.dll               6.1.7601.19106              Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 6.1.7601.17514              Greek_Latin Keyboard Layout
    kbdgr.dll                  6.1.7600.16385              German Keyboard Layout
    kbdgr1.dll                 6.1.7601.17514              German_IBM Keyboard Layout
    kbdgrlnd.dll               6.1.7600.16385              Greenlandic Keyboard Layout
    kbdhau.dll                 6.1.7600.16385              Hausa Keyboard Layout
    kbdhe.dll                  6.1.7600.16385              Greek Keyboard Layout
    kbdhe220.dll               6.1.7600.16385              Greek IBM 220 Keyboard Layout
    kbdhe319.dll               6.1.7600.16385              Greek IBM 319 Keyboard Layout
    kbdheb.dll                 6.1.7600.16385              KBDHEB Keyboard Layout
    kbdhela2.dll               6.1.7600.16385              Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               6.1.7600.16385              Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                6.1.7600.16385              Greek_Polytonic Keyboard Layout
    kbdhu.dll                  6.1.7600.16385              Hungarian Keyboard Layout
    kbdhu1.dll                 6.1.7600.16385              Hungarian 101-key Keyboard Layout
    kbdibm02.dll               6.1.7600.16385              JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 6.1.7600.16385              Igbo Keyboard Layout
    kbdic.dll                  6.1.7600.16385              Icelandic Keyboard Layout
    kbdinasa.dll               6.1.7600.16385              Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               6.1.7600.16385              Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               6.1.7600.16385              Bengali (Inscript) Keyboard Layout
    kbdinben.dll               6.1.7601.17514              Bengali Keyboard Layout
    kbdindev.dll               6.1.7600.16385              Devanagari Keyboard Layout
    kbdinguj.dll               6.1.7600.16385              Gujarati Keyboard Layout
    kbdinhin.dll               6.1.7601.17514              Hindi Keyboard Layout
    kbdinkan.dll               6.1.7601.17514              Kannada Keyboard Layout
    kbdinmal.dll               6.1.7600.16385              Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               6.1.7601.17514              Marathi Keyboard Layout
    kbdinori.dll               6.1.7601.17514              Oriya Keyboard Layout
    kbdinpun.dll               6.1.7600.16385              Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               6.1.7601.17514              Tamil Keyboard Layout
    kbdintel.dll               6.1.7601.17514              Telugu Keyboard Layout
    kbdinuk2.dll               6.1.7600.16385              Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  6.1.7600.16385              Irish Keyboard Layout
    kbdit.dll                  6.1.7600.16385              Italian Keyboard Layout
    kbdit142.dll               6.1.7600.16385              Italian 142 Keyboard Layout
    kbdiulat.dll               6.1.7600.16385              Inuktitut Latin Keyboard Layout
    kbdjpn.dll                 6.1.7600.16385              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 6.1.7600.16385              Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                6.1.7600.16385              Cambodian Standard Keyboard Layout
    kbdkor.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout Stub driver
    kbdkyr.dll                 6.1.7600.16385              Kyrgyz Keyboard Layout
    kbdla.dll                  6.1.7600.16385              Latin-American Spanish Keyboard Layout
    kbdlao.dll                 6.1.7600.16385              Lao Standard Keyboard Layout
    kbdlk41a.dll               6.1.7601.17514              DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  6.1.7600.16385              Lithuania Keyboard Layout
    kbdlt1.dll                 6.1.7601.17514              Lithuanian Keyboard Layout
    kbdlt2.dll                 6.1.7600.16385              Lithuanian Standard Keyboard Layout
    kbdlv.dll                  6.1.7600.16385              Latvia Keyboard Layout
    kbdlv1.dll                 6.1.7600.16385              Latvia-QWERTY Keyboard Layout
    kbdmac.dll                 6.1.7600.16385              Macedonian (FYROM) Keyboard Layout
    kbdmacst.dll               6.1.7600.16385              Macedonian (FYROM) - Standard Keyboard Layout
    kbdmaori.dll               6.1.7601.17514              Maori Keyboard Layout
    kbdmlt47.dll               6.1.7600.16385              Maltese 47-key Keyboard Layout
    kbdmlt48.dll               6.1.7600.16385              Maltese 48-key Keyboard Layout
    kbdmon.dll                 6.1.7601.17514              Mongolian Keyboard Layout
    kbdmonmo.dll               6.1.7600.16385              Mongolian (Mongolian Script) Keyboard Layout
    kbdne.dll                  6.1.7600.16385              Dutch Keyboard Layout
    kbdnec.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               6.1.7600.16385              JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                6.1.7601.17514              Nepali Keyboard Layout
    kbdno.dll                  6.1.7600.16385              Norwegian Keyboard Layout
    kbdno1.dll                 6.1.7600.16385              Norwegian with Sami Keyboard Layout
    kbdnso.dll                 6.1.7600.16385              Sesotho sa Leboa Keyboard Layout
    kbdpash.dll                6.1.7600.16385              Pashto (Afghanistan) Keyboard Layout
    kbdpl.dll                  6.1.7600.16385              Polish Keyboard Layout
    kbdpl1.dll                 6.1.7600.16385              Polish Programmer's Keyboard Layout
    kbdpo.dll                  6.1.7601.17514              Portuguese Keyboard Layout
    kbdro.dll                  6.1.7600.16385              Romanian (Legacy) Keyboard Layout
    kbdropr.dll                6.1.7600.16385              Romanian (Programmers) Keyboard Layout
    kbdrost.dll                6.1.7600.16385              Romanian (Standard) Keyboard Layout
    kbdru.dll                  6.1.7601.18528              Russian Keyboard Layout
    kbdru1.dll                 6.1.7601.18528              Russia(Typewriter) Keyboard Layout
    kbdsf.dll                  6.1.7601.17514              Swiss French Keyboard Layout
    kbdsg.dll                  6.1.7601.17514              Swiss German Keyboard Layout
    kbdsl.dll                  6.1.7600.16385              Slovak Keyboard Layout
    kbdsl1.dll                 6.1.7600.16385              Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               6.1.7600.16385              Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               6.1.7600.16385              Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 6.1.7600.16385              Sinhala Keyboard Layout
    kbdsorex.dll               6.1.7600.16385              Sorbian Extended Keyboard Layout
    kbdsors1.dll               6.1.7600.16385              Sorbian Standard Keyboard Layout
    kbdsorst.dll               6.1.7600.16385              Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  6.1.7600.16385              Spanish Keyboard Layout
    kbdsw.dll                  6.1.7600.16385              Swedish Keyboard Layout
    kbdsw09.dll                6.1.7600.16385              Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                6.1.7600.16385              Syriac Standard Keyboard Layout
    kbdsyr2.dll                6.1.7600.16385              Syriac Phoenetic Keyboard Layout
    kbdtajik.dll               6.1.7601.17514              Tajik Keyboard Layout
    kbdtat.dll                 6.1.7601.18528              Tatar (Legacy) Keyboard Layout
    kbdth0.dll                 6.1.7600.16385              Thai Kedmanee Keyboard Layout
    kbdth1.dll                 6.1.7600.16385              Thai Pattachote Keyboard Layout
    kbdth2.dll                 6.1.7600.16385              Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 6.1.7600.16385              Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtiprc.dll               6.1.7600.16385              Tibetan (PRC) Keyboard Layout
    kbdtuf.dll                 6.1.7601.17514              Turkish F Keyboard Layout
    kbdtuq.dll                 6.1.7601.17514              Turkish Q Keyboard Layout
    kbdturme.dll               6.1.7601.17514              Turkmen Keyboard Layout
    kbdughr.dll                6.1.7600.16385              Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               6.1.7601.17514              Uyghur Keyboard Layout
    kbduk.dll                  6.1.7600.16385              United Kingdom Keyboard Layout
    kbdukx.dll                 6.1.7600.16385              United Kingdom Extended Keyboard Layout
    kbdur.dll                  6.1.7600.16385              Ukrainian Keyboard Layout
    kbdur1.dll                 6.1.7600.16385              Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                6.1.7600.16385              Urdu Keyboard Layout
    kbdus.dll                  6.1.7601.17514              United States Keyboard Layout
    kbdusa.dll                 6.1.7600.16385              US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 6.1.7600.16385              Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 6.1.7600.16385              Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 6.1.7600.16385              US Multinational Keyboard Layout
    kbduzb.dll                 6.1.7600.16385              Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                6.1.7600.16385              Vietnamese Keyboard Layout
    kbdwol.dll                 6.1.7600.16385              Wolof Keyboard Layout
    kbdyak.dll                 6.1.7601.18528              Sakha - Russia Keyboard Layout
    kbdyba.dll                 6.1.7600.16385              Yoruba Keyboard Layout
    kbdycc.dll                 6.1.7600.16385              Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 6.1.7600.16385              Serbian (Latin) Keyboard Layout
    kerberos.dll               6.1.7601.19160                Kerberos
    kernel32.dll               6.1.7601.19160                Windows NT BASE API
    kernelbase.dll             6.1.7601.19160                Windows NT BASE API
    keyiso.dll                 6.1.7600.16385                 CNG
    keymgr.dll                 6.1.7600.16385                  
    korwbrkr.dll               6.1.7600.16385              korwbrkr
    ksuser.dll                 6.1.7601.19091              User CSA Library
    ktmw32.dll                 6.1.7600.16385              Windows KTM Win32 Client DLL
    l2gpstore.dll              6.1.7600.16385              Policy Storage dll
    l2nacp.dll                 6.1.7600.16385                 Onex Windows
    l2sechc.dll                6.1.7600.16385                    2
    lagarith.dll               1.3.27.0                    Lagarith
    laprxy.dll                 12.0.7600.16385             Windows Media Logagent Proxy
    libeay32.dll               1.0.1.5                     OpenSSL Shared Library
    libssl32.dll               1.0.1.5                     OpenSSL Shared Library
    licmgr10.dll               11.0.9600.16428              (DLL)    Microsoft
    linkinfo.dll               6.1.7600.16385              Windows Volume Tracking
    loadperf.dll               6.1.7600.16385                  
    localsec.dll               6.1.7601.17514               MMC "   "
    locationapi.dll            6.1.7600.16385              Microsoft Windows Location API
    loghours.dll               6.1.7600.16385               
    logoncli.dll               6.1.7601.17514              Net Logon Client DLL
    lpk.dll                    6.1.7601.19146              Language Pack
    lsmproxy.dll               6.1.7601.17514              LSM interfaces proxy Dll
    luainstall.dll             6.1.7601.17514              Lua manifest install
    lz32.dll                   6.1.7600.16385              LZ Expand/Compress API DLL
    macdll.dll                 3.9.9.1                     Monkey's Audio DLL Library
    magnification.dll          6.1.7600.16385               API  ()
    mantle32.dll               26.20.15029.27016           Mantle loader
    mantleaxl32.dll            26.20.15029.27016           Mantle extension library
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    maxxaudioaposhell.dll      4.10.8.0                    MaxxAudio APO Shell
    mcewmdrmndbootstrap.dll    1.3.2302.0                  Windows Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
    mciavi32.dll               6.1.7601.17514               MCI Video  Windows
    mcicda.dll                 6.1.7600.16385               MCI   cdaudio
    mciqtz32.dll               6.6.7601.17514               MCI DirectShow
    mciseq.dll                 6.1.7600.16385               MCI   MIDI
    mciwave.dll                6.1.7600.16385               MCI   
    mctres.dll                 6.1.7600.16385                MCT
    mdminst.dll                6.1.7600.16385               
    mediametadatahandler.dll   6.1.7601.17514              Media Metadata Handler
    mf.dll                     12.0.7601.19091               
    mf3216.dll                 6.1.7600.16385              32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               6.1.7600.16385              Media Foundation AAC Encoder
    mfc100.dll                 10.0.40219.325              MFCDLL Shared Library - Retail Version
    mfc100chs.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100cht.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100deu.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100enu.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100esn.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100fra.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100ita.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100jpn.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100kor.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100rus.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100u.dll                10.0.40219.325              MFCDLL Shared Library - Retail Version
    mfc110.dll                 11.0.60610.1                MFCDLL Shared Library - Retail Version
    mfc110chs.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110cht.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110deu.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110enu.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110esn.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110fra.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110ita.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110jpn.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110kor.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110rus.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110u.dll                11.0.60610.1                MFCDLL Shared Library - Retail Version
    mfc120.dll                 12.0.21005.1                MFCDLL Shared Library - Retail Version
    mfc120chs.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120cht.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120deu.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120enu.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120esn.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120fra.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120ita.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120jpn.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120kor.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120rus.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120u.dll                12.0.21005.1                MFCDLL Shared Library - Retail Version
    mfc140.dll                 14.23.27820.0               MFCDLL Shared Library - Retail Version
    mfc140chs.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140cht.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140deu.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140enu.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140esn.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140fra.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140ita.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140jpn.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140kor.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140rus.dll              14.23.27820.0               MFC Language Specific Resources
    mfc140u.dll                14.23.27820.0               MFCDLL Shared Library - Retail Version
    mfc40.dll                  4.1.0.6151                    MFCDLL -  
    mfc40u.dll                 4.1.0.6151                    MFCDLL -  
    mfc42.dll                  6.6.8064.0                    MFCDLL -  
    mfc42u.dll                 6.6.8064.0                    MFCDLL -  
    mfc70.dll                  7.0.9975.0                  MFCDLL Shared Library - Retail Version
    mfc70chs.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70cht.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70deu.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70enu.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70esp.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70fra.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70ita.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70jpn.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70kor.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70u.dll                 7.0.9975.0                  MFCDLL Shared Library - Retail Version
    mfc71.dll                  7.10.6101.0                 MFCDLL Shared Library - Retail Version
    mfc71chs.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71cht.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71deu.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71enu.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71esp.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71fra.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71ita.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71jpn.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71kor.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71u.dll                 7.10.6101.0                 MFCDLL Shared Library - Retail Version
    mfcm100.dll                10.0.40219.325              MFC Managed Library - Retail Version
    mfcm100u.dll               10.0.40219.325              MFC Managed Library - Retail Version
    mfcm110.dll                11.0.60610.1                MFC Managed Library - Retail Version
    mfcm110u.dll               11.0.60610.1                MFC Managed Library - Retail Version
    mfcm120.dll                12.0.21005.1                MFC Managed Library - Retail Version
    mfcm120u.dll               12.0.21005.1                MFC Managed Library - Retail Version
    mfcm140.dll                14.23.27820.0               MFC Managed Library - Retail Version
    mfcm140u.dll               14.23.27820.0               MFC Managed Library - Retail Version
    mfcsubs.dll                2001.12.8530.16385          COM+
    mfds.dll                   12.0.7601.19145             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                6.1.7600.16385              Media Foundation DV Decoder
    mferror.dll                12.0.7601.19091                
    mfh264enc.dll              6.1.7600.16385              Media Foundation H264 Encoder
    mfmjpegdec.dll             6.1.7600.16385              Media Foundation MJPEG Decoder
    mfplat.dll                 12.0.7601.19091             Media Foundation Platform DLL
    mfplay.dll                 12.0.7601.17514             Media Foundation Playback API DLL
    mfps.dll                   12.0.7601.19091             Media Foundation Proxy DLL
    mfreadwrite.dll            12.0.7601.17514             Media Foundation ReadWrite DLL
    mfvdsp.dll                 6.1.7601.19091              Windows Media Foundation Video DSP Components
    mfwmaaec.dll               6.1.7601.19091              Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                6.1.7600.16385              Microsoft SNMP Manager API (uses WinSNMP)
    midimap.dll                6.1.7600.16385              Microsoft MIDI Mapper
    migisol.dll                6.1.7601.17514              Migration System Isolation Layer
    miguiresource.dll          6.1.7600.16385               MIG wini32
    mimefilt.dll               2008.0.7601.17514            MIME
    mlang.dll                  6.1.7600.16385               DLL  
    mlc.dll                                                
    mmcbase.dll                6.1.7600.16385                DLL MMC
    mmci.dll                   6.1.7600.16385                
    mmcico.dll                 6.1.7600.16385              Media class co-installer
    mmcndmgr.dll               6.1.7601.17514                 MMC
    mmcshext.dll               6.1.7600.16385              MMC Shell Extension DLL
    mmdevapi.dll               6.1.7601.17514              MMDevice API
    mmres.dll                  6.1.7600.16385               
    modemui.dll                6.1.7600.16385                Windows
    moricons.dll               6.1.7600.16385              Windows NT Setup Icon Resources Library
    mp3dmod.dll                6.1.7601.19091              Microsoft MP3 Decoder DMO
    mp43decd.dll               6.1.7601.19091              Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               6.1.7601.19091              Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               6.1.7601.19091              Windows Media MPEG-4 Video Decoder
    mpr.dll                    6.1.7600.16385                   
    mprapi.dll                 6.1.7601.17514              Windows NT MP Router Administration DLL
    mprddm.dll                 6.1.7601.17514                  
    mprdim.dll                 6.1.7600.16385                
    mprmsg.dll                 6.1.7600.16385               (DLL)    
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               6.1.7601.17514              Microsoft AC-3 Encoder
    msacm32.dll                6.1.7600.16385                 Microsoft
    msadce.dll                 6.1.7601.17514              OLE DB Cursor Engine
    msadce.dll                 6.1.7601.17514              OLE DB Cursor Engine
    msadcer.dll                6.1.7600.16385              OLE DB Cursor Engine Resources
    msadcer.dll                6.1.7600.16385              OLE DB Cursor Engine Resources
    msadcf.dll                 6.1.7601.17514              Remote Data Services Data Factory
    msadcf.dll                 6.1.7601.17514              Remote Data Services Data Factory
    msadcfr.dll                6.1.7600.16385              Remote Data Services Data Factory Resources
    msadcfr.dll                6.1.7600.16385              Remote Data Services Data Factory Resources
    msadco.dll                 6.1.7601.17857              Remote Data Services Data Control
    msadco.dll                 6.1.7601.17857              Remote Data Services Data Control
    msadcor.dll                6.1.7600.16385              Remote Data Services Data Control Resources
    msadcor.dll                6.1.7600.16385              Remote Data Services Data Control Resources
    msadcs.dll                 6.1.7601.17514              Remote Data Services ISAPI Library
    msadcs.dll                 6.1.7601.17514              Remote Data Services ISAPI Library
    msadds.dll                 6.1.7600.16385              OLE DB Data Shape Provider
    msadds.dll                 6.1.7600.16385              OLE DB Data Shape Provider
    msaddsr.dll                6.1.7600.16385               OLE DB Data Shape Provider Resources
    msaddsr.dll                6.1.7600.16385               OLE DB Data Shape Provider Resources
    msader15.dll               6.1.7600.16385              ActiveX Data Objects Resources
    msader15.dll               6.1.7600.16385              ActiveX Data Objects Resources
    msado15.dll                6.1.7601.17857              ActiveX Data Objects
    msado15.dll                6.1.7601.17857              ActiveX Data Objects
    msadomd.dll                6.1.7601.17857              ActiveX Data Objects (Multi-Dimensional)
    msadomd.dll                6.1.7601.17857              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               6.1.7601.17857              Microsoft ActiveX Data Objects Recordset
    msador15.dll               6.1.7601.17857              Microsoft ActiveX Data Objects Recordset
    msadox.dll                 6.1.7601.17857              ActiveX Data Objects Extensions
    msadox.dll                 6.1.7601.17857              ActiveX Data Objects Extensions
    msadrh15.dll               6.1.7600.16385              ActiveX Data Objects Rowset Helper
    msadrh15.dll               6.1.7600.16385              ActiveX Data Objects Rowset Helper
    msafd.dll                  6.1.7600.16385              Microsoft Windows Sockets 2.0 Service Provider
    msasn1.dll                 6.1.7601.17514              ASN.1 Runtime APIs
    msaudite.dll               6.1.7601.19160                 
    mscandui.dll               6.1.7600.16385                MSCANDUI
    mscat32.dll                6.1.7600.16385              MSCAT32 Forwarder DLL
    msclmd.dll                 6.1.7601.17514              Microsoft Class Mini-driver
    mscms.dll                  6.1.7601.17514              DLL-    
    mscoree.dll                4.0.40305.0                 Microsoft .NET Runtime Execution Engine
    mscorier.dll               2.0.50727.5483               IE    Microsoft .NET
    mscories.dll               2.0.50727.5483              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               6.1.7600.16385              ODBC Code Page Translator Resources
    mscpxl32.dll               6.1.7600.16385                 ODBC
    msctf.dll                  6.1.7601.18731                MSCTF
    msctfmonitor.dll           6.1.7600.16385              MsCtfMonitor DLL
    msctfp.dll                 6.1.7600.16385              MSCTFP Server DLL
    msctfui.dll                6.1.7600.16385                MSCTFUI
    msdadc.dll                 6.1.7600.16385              OLE DB Data Conversion Stub
    msdadiag.dll               6.1.7600.16385              Built-In Diagnostics
    msdaenum.dll               6.1.7600.16385              OLE DB Root Enumerator Stub
    msdaer.dll                 6.1.7600.16385              OLE DB Error Collection Stub
    msdaora.dll                6.1.7601.19135              OLE DB Provider for Oracle
    msdaorar.dll               6.1.7600.16385              OLE DB Provider for Oracle Resources
    msdaosp.dll                6.1.7601.17632              OLE DB Simple Provider
    msdaosp.dll                6.1.7601.17632              OLE DB Simple Provider
    msdaprsr.dll               6.1.7600.16385                OLE DB Persistence Services
    msdaprsr.dll               6.1.7600.16385                OLE DB Persistence Services
    msdaprst.dll               6.1.7600.16385              OLE DB Persistence Services
    msdaprst.dll               6.1.7600.16385              OLE DB Persistence Services
    msdaps.dll                 6.1.7600.16385              OLE DB Interface Proxies/Stubs
    msdaps.dll                 6.1.7600.16385              OLE DB Interface Proxies/Stubs
    msdarem.dll                6.1.7601.17514              OLE DB Remote Provider
    msdarem.dll                6.1.7601.17514              OLE DB Remote Provider
    msdaremr.dll               6.1.7600.16385              OLE DB Remote Provider Resources
    msdaremr.dll               6.1.7600.16385              OLE DB Remote Provider Resources
    msdart.dll                 6.1.7600.16385              OLE DB Runtime Routines
    msdasc.dll                 6.1.7600.16385              OLE DB Service Components Stub
    msdasql.dll                6.1.7601.17514              OLE DB Provider for ODBC Drivers
    msdasql.dll                6.1.7601.17514              OLE DB Provider for ODBC Drivers
    msdasqlr.dll               6.1.7600.16385              OLE DB Provider for ODBC Drivers Resources
    msdasqlr.dll               6.1.7600.16385              OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                6.1.7600.16385              OLE DB Implementation Support Routines
    msdatl3.dll                6.1.7600.16385              OLE DB Implementation Support Routines
    msdatt.dll                 6.1.7600.16385              OLE DB Temporary Table Services
    msdaurl.dll                6.1.7600.16385              OLE DB RootBinder Stub
    msdelta.dll                6.1.7600.16385              Microsoft Patch Engine
    msdfmap.dll                6.1.7601.17514              Data Factory Handler
    msdfmap.dll                6.1.7601.17514              Data Factory Handler
    msdmo.dll                  6.6.7601.17514              DMO Runtime
    msdrm.dll                  6.1.7601.18332                 Windows
    msdtcprx.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtcuiu.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.8530.16385               Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9756.0                  Microsoft Jet Excel Isam
    msfeeds.dll                11.0.9600.18231             Microsoft Feeds Manager
    msfeedsbs.dll              11.0.9600.16428               - ()
    msftedit.dll               5.41.21.2510                Rich Text Edit Control, v4.1
    mshtml.dll                 11.0.9600.18231               HTML Microsoft
    mshtmldac.dll              11.0.9600.18231             DAC for Trident DOM
    mshtmled.dll               11.0.9600.18231             Microsoft HTML Editing Component
    mshtmler.dll               11.0.9600.16428                 HTML (Microsoft)
    mshtmlmedia.dll            11.0.9600.18231             Microsoft (R) HTML Media DLL
    msi.dll                    5.0.7601.18896              Windows Installer
    msidcrl30.dll              6.1.7600.16385              IDCRL Dynamic Link Library
    msident.dll                6.1.7600.16385                (Microsoft)
    msidle.dll                 6.1.7600.16385              User Idle Monitor
    msidntld.dll               6.1.7600.16385                (Microsoft)
    msieftp.dll                6.1.7601.18300                Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.7601.18896              Windows installer
    msiltcfg.dll               5.0.7600.16385              Windows Installer Configuration API Stub
    msimg32.dll                6.1.7600.16385              GDIEXT Client DLL
    msimsg.dll                 5.0.7601.18896                 Windows
    msimtf.dll                 6.1.7600.16385              Active IMM Server DLL
    msisip.dll                 5.0.7600.16385              MSI Signature SIP Provider
    msjet40.dll                4.0.9756.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9756.0                  
    msjint40.dll               4.0.9756.0                       Microsoft Jet
    msjro.dll                  6.1.7601.17857              Jet and Replication Objects
    msjter40.dll               4.0.9756.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9756.0                  Microsoft Jet Expression Service
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9756.0                  Microsoft Jet Lotus 1-2-3 Isam
    msmpeg2adec.dll            6.1.7601.23285              Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             6.1.7601.19091               Microsoft MPEG-2
    msmpeg2vdec.dll            12.0.9200.17037             Microsoft DTV-DVD Video Decoder
    msnetobj.dll               11.0.7601.18741             DRM ActiveX Network Object
    msobjs.dll                 6.1.7601.19160                 
    msoeacct.dll               6.1.7600.16385              Microsoft Internet Account Manager
    msoert2.dll                6.1.7600.16385              Microsoft Windows Mail RT Lib
    msorc32r.dll               6.1.7600.16385                ODBC  Oracle
    msorcl32.dll               6.1.7601.19135              ODBC Driver for Oracle
    mspatcha.dll               6.1.7600.16385              Microsoft File Patch Application API
    mspbde40.dll               4.0.9756.0                  Microsoft Jet Paradox Isam
    msports.dll                6.1.7600.16385                 
    msrating.dll               11.0.9600.18231                  
    msrd2x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrdc.dll                  6.1.7600.16385              Remote Differential Compression COM server
    msrdpwebaccess.dll         6.3.9600.16415              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9756.0                  Microsoft Replication Library
    msrle32.dll                6.1.7601.17514              Microsoft RLE Compressor
    msscntrs.dll               7.0.7601.17610              msscntrs.dll
    msscp.dll                  11.0.7601.18741             Windows Media Secure Content Provider
    mssha.dll                  6.1.7600.16385                  Windows
    msshavmsg.dll              6.1.7600.16385                     Windows
    msshooks.dll               7.0.7600.16385              MSSHooks.dll
    mssign32.dll               6.1.7600.16385               API  
    mssip32.dll                6.1.7600.16385              MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.7600.16385              mssitlb
    mssph.dll                  7.0.7601.17610                 Microsoft
    mssphtb.dll                7.0.7601.17610              Outlook MSSearch Connector
    mssprxy.dll                7.0.7600.16385              Microsoft Search Proxy
    mssrch.dll                 7.0.7601.17610              mssrch.dll
    msstdfmt.dll               6.1.98.16                   Microsoft Standard Data Formating Object DLL
    msstkprp.dll               6.1.98.16                   msprop32.ocx
    mssvp.dll                  7.0.7601.17610               Vista MSSearch
    msswch.dll                 6.1.7600.16385              msswch
    mstask.dll                 6.1.7601.17514                 
    mstext40.dll               4.0.9756.0                  Microsoft Jet Text Isam
    mstscax.dll                6.3.9600.17930              ActiveX-    
    msutb.dll                  6.1.7601.17514               (DLL)  MSUTB
    msv1_0.dll                 6.1.7601.19160              Microsoft Authentication Package v1.0
    msvbvm50.dll               5.2.82.44                   Visual Basic Virtual Machine
    msvbvm60.dll               6.0.98.15                   Visual Basic Virtual Machine
    msvci70.dll                7.0.9955.0                  Microsoft C++ Runtime Library
    msvcirt.dll                7.0.7600.16385              Windows NT IOStreams DLL
    msvcp100.dll               10.0.40219.325              Microsoft C Runtime Library
    msvcp110.dll               11.0.51106.1                Microsoft C Runtime Library
    msvcp110_clr0400.dll       14.7.3062.0                 Microsoft .NET Framework
    msvcp120.dll               12.0.21005.1                Microsoft C Runtime Library
    msvcp120_clr0400.dll       12.0.52519.0                Microsoft C Runtime Library
    msvcp140.dll               14.23.27820.0               Microsoft C Runtime Library
    msvcp140_1.dll             14.23.27820.0               Microsoft C Runtime Library _1
    msvcp140_2.dll             14.23.27820.0               Microsoft C Runtime Library _2
    msvcp140_codecvt_ids.dll   14.23.27820.0               Microsoft C Runtime Library _codecvt_ids
    msvcp60.dll                7.0.7600.16385              Windows NT C++ Runtime Library DLL
    msvcp70.dll                7.0.9466.0                  Microsoft C++ Runtime Library
    msvcp71.dll                7.10.6052.0                 Microsoft C++ Runtime Library
    msvcr100.dll               10.0.40219.325              Microsoft C Runtime Library
    msvcr100_clr0400.dll       14.7.3062.0                 Microsoft .NET Framework
    msvcr110.dll               11.0.51106.1                Microsoft C Runtime Library
    msvcr110_clr0400.dll       14.7.3062.0                 Microsoft .NET Framework
    msvcr120.dll               12.0.21005.1                Microsoft C Runtime Library
    msvcr120_clr0400.dll       12.0.52519.0                Microsoft C Runtime Library
    msvcr70.dll                7.0.9981.0                  Microsoft C Runtime Library
    msvcr71.dll                7.10.7031.4                 Microsoft C Runtime Library
    msvcrt.dll                 7.0.7601.17744              Windows NT CRT DLL
    msvcrt10.dll                                           
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               6.1.7600.16385              VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                6.1.7601.17514               Microsoft Video  Windows
    msvidc32.dll               6.1.7601.17514                Microsoft Video 1
    msvidctl.dll               6.5.7601.17514               ActiveX  
    mswdat10.dll               4.0.9756.0                  Microsoft Jet Sort Tables
    mswmdm.dll                 12.0.7600.16385               Windows Media Device Manager
    mswsock.dll                6.1.7601.18254                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9756.0                    Microsoft Jet
    msxactps.dll               6.1.7600.16385              OLE DB Transaction Proxies/Stubs
    msxactps.dll               6.1.7600.16385              OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9756.0                  Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.7601.18980            MSXML 3.0 SP11
    msxml3r.dll                8.110.7601.18980            XML Resources
    msxml6.dll                 6.30.7601.18980             MSXML 6.0 SP3
    msxml6r.dll                6.30.7601.18980             XML Resources
    msyuv.dll                  6.1.7601.17514              Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.8531.17514          Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.8530.16385          COM+
    mtxex.dll                  2001.12.8530.16385          COM+
    mtxlegih.dll               2001.12.8530.16385          COM+
    mtxoci.dll                 2001.12.8531.19135          Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           6.1.7601.17514              MUI Callback for font registry settings
    mycomput.dll               6.1.7600.16385               
    mydocs.dll                 6.1.7601.17514                 " "
    napcrypt.dll               6.1.7601.17514              NAP Cryptographic API helper
    napdsnap.dll               6.1.7601.17514               GPEdit    
    naphlpr.dll                6.1.7601.17514              NAP client config API helper
    napinsp.dll                6.1.7600.16385                    
    napipsec.dll               6.1.7600.16385                      IPSec
    napmontr.dll               6.1.7600.16385                NAP  Netsh
    nativehooks.dll            6.1.7600.16385              Microsoft Narrator Native hook handler
    naturallanguage6.dll       6.1.7601.17514              Natural Language Development Platform 6
    ncdprop.dll                6.1.7600.16385                 
    nci.dll                    6.1.7601.17514              CoInstaller: NET
    ncobjapi.dll               6.1.7600.16385              Microsoft Windows Operating System
    ncrypt.dll                 6.1.7601.19160                (Windows)
    ncryptui.dll               6.1.7601.17514               UI     Windows
    ncsi.dll                   6.1.7601.18685                 
    nddeapi.dll                6.1.7600.16385              Network DDE Share Management APIs
    ndfapi.dll                 6.1.7600.16385              API    
    ndfetw.dll                 6.1.7600.16385              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         6.1.7600.16385              Network Diagnostic Framework HC Discovery API
    ndiscapcfg.dll             6.1.7600.16385              NdisCap Notify Object
    ndishc.dll                 6.1.7600.16385                NDIS
    ndproxystub.dll            6.1.7600.16385              Network Diagnostic Engine Proxy/Stub
    negoexts.dll               6.1.7600.16385              NegoExtender Security Package
    netapi32.dll               6.1.7601.17887              Net Win32 API DLL
    netbios.dll                6.1.7600.16385              NetBIOS Interface Library
    netcenter.dll              6.1.7601.17514                 -  
    netcfgx.dll                6.1.7601.17514                
    netcorehc.dll              6.1.7601.17964                   
    netdiagfx.dll              6.1.7601.17514                
    netevent.dll               6.1.7601.17964                
    netfxperf.dll              4.0.40305.0                 Extensible Performance Counter Shim
    neth.dll                   6.1.7600.16385                 
    netid.dll                  6.1.7601.17514                  
    netiohlp.dll               6.1.7601.17514               DLL   Netio
    netjoin.dll                6.1.7601.17514              Domain Join DLL
    netlogon.dll               6.1.7601.17514                 Net Logon
    netmsg.dll                 6.1.7600.16385                
    netplwiz.dll               6.1.7601.17514                   
    netprof.dll                6.1.7600.16385                 
    netprofm.dll               6.1.7600.16385                
    netshell.dll               6.1.7601.17514                
    netutils.dll               6.1.7601.17514              Net Win32 API Helpers DLL
    networkexplorer.dll        6.1.7601.17514               
    networkitemfactory.dll     6.1.7600.16385                
    networkmap.dll             6.1.7601.17514               
    newdev.dll                 6.0.5054.0                    
    nlaapi.dll                 6.1.7601.18685              Network Location Awareness 2
    nlhtml.dll                 2008.0.7600.16385            HTML
    nlmgp.dll                  6.1.7600.16385                 
    nlmsprep.dll               6.1.7600.16385              Network List Manager Sysprep Module
    nlsbres.dll                6.1.7601.19106              NLSBuild resource DLL
    nlsdata0000.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0001.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0002.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0003.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0007.dll            6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlsdata0009.dll            6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlsdata000a.dll            6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlsdata000c.dll            6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlsdata000d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata000f.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0010.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0011.dll            6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlsdata0013.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0018.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0019.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0020.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0021.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0022.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0024.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0026.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0027.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata002a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0039.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata003e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0045.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0046.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0047.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0049.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004c.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0414.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0416.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0816.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata081a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0c1a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdl.dll                  6.1.7600.16385              Nls Downlevel DLL
    nlslexicons0001.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0002.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0003.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0007.dll        6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlslexicons0009.dll        6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlslexicons000a.dll        6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlslexicons000c.dll        6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlslexicons000d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons000f.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0010.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0011.dll        6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlslexicons0013.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0018.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0019.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0020.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0021.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0022.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0024.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0026.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0027.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons002a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0039.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons003e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0045.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0046.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0047.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0049.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004c.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0414.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0416.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0816.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons081a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0c1a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsmodels0011.dll          6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    normaliz.dll               6.1.7600.16385              Unicode Normalization DLL
    npmproxy.dll               6.1.7600.16385              Network List Manager Proxy
    nshhttp.dll                6.1.7600.16385               DLL netsh  HTTP
    nshipsec.dll               6.1.7601.17514               DLL  IPSec  Net
    nshwfp.dll                 6.1.7601.18283                  Windows  Netsh
    nsi.dll                    6.1.7600.16385              NSI User-mode interface DLL
    ntdll.dll                  6.1.7601.19160                NT
    ntdsapi.dll                6.1.7600.16385              Active Directory Domain Services API
    ntlanman.dll               6.1.7601.17514              Microsoft LAN Manager
    ntlanui2.dll               6.1.7600.16385                  
    ntmarta.dll                6.1.7600.16385               Windows NT MARTA
    ntprint.dll                6.1.7601.17514                  
    ntshrui.dll                6.1.7601.17755               ,    
    ntvdm64.dll                6.1.7601.19160              16-   NT64
    objsel.dll                 6.1.7601.18409                
    occache.dll                11.0.9600.18231                 
    ocsetapi.dll               6.1.7601.17514              Windows Optional Component Setup API
    odbc32.dll                 6.1.7601.17514              ODBC Driver Manager
    odbc32gt.dll               6.1.7600.16385              ODBC Driver Generic Thunk
    odbcbcp.dll                6.1.7600.16385              BCP for ODBC
    odbcconf.dll               6.1.7601.17514              ODBC Driver Configuration Program
    odbccp32.dll               6.1.7601.17632              ODBC Installer
    odbccr32.dll               6.1.7601.17632              ODBC Cursor Library
    odbccu32.dll               6.1.7601.17632              ODBC Cursor Library
    odbcint.dll                6.1.7600.16385              ODBC Resources
    odbcji32.dll               6.1.7600.16385              Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               6.1.7601.17632              Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               6.1.7601.17632              ODBC Driver Manager Trace
    oddbse32.dll               6.1.7600.16385              ODBC (3.0) driver for DBase
    odexl32.dll                6.1.7600.16385              ODBC (3.0) driver for Excel
    odfox32.dll                6.1.7600.16385              ODBC (3.0) driver for FoxPro
    odpdx32.dll                6.1.7600.16385              ODBC (3.0) driver for Paradox
    odtext32.dll               6.1.7600.16385              ODBC (3.0) driver for text files
    offfilt.dll                2008.0.7600.16385            OFFICE
    ogldrv.dll                 6.1.7600.16385              MSOGL
    ole2.dll                   2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    ole2disp.dll               2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole2nls.dll                2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole32.dll                  6.1.7601.19131              Microsoft OLE   Windows
    oleacc.dll                 7.0.0.0                     Active Accessibility Core Component
    oleacchooks.dll            7.0.0.0                     Active Accessibility Event Hooks Library
    oleaccrc.dll               7.0.0.0                     Active Accessibility Resource DLL
    oleaut32.dll               6.1.7601.19144              
    olecli32.dll               6.1.7600.16385                OLE
    oledb32.dll                6.1.7601.17514              OLE DB Core Services
    oledb32.dll                6.1.7601.17514              OLE DB Core Services
    oledb32r.dll               6.1.7600.16385                 OLE DB
    oledb32r.dll               6.1.7600.16385                 OLE DB
    oledlg.dll                 6.1.7600.16385                 OLE
    oleprn.dll                 6.1.7600.16385              Oleprn DLL
    olepro32.dll               6.1.7601.17514              
    oleres.dll                 6.1.7600.16385                OLE
    olesvr32.dll               6.1.7600.16385              Object Linking and Embedding Server Library
    olethk32.dll               6.1.7601.17514              Microsoft OLE for Windows
    onex.dll                   6.1.7601.17514                IEEE 802.1X
    onexui.dll                 6.1.7601.17514                 IEEE 802.1X
    onlineidcpl.dll            6.1.7601.17514                -  
    oobefldr.dll               6.1.7601.17514                
    opcservices.dll            6.1.7601.17514              Native Code OPC Services Library
    openal32.dll               6.14.357.25                 Standard OpenAL(TM) Implementation
    opencl.dll                 2.2.1.0                     OpenCL Client DLL
    opengl32.dll               6.1.7600.16385              OpenGL Client DLL
    osbaseln.dll               6.1.7600.16385              Service Reporting API
    osuninst.dll               6.1.7600.16385              Uninstall Interface
    p2p.dll                    6.1.7600.16385                
    p2pcollab.dll              6.1.7600.16385                  
    p2pgraph.dll               6.1.7600.16385              Peer-to-Peer Graphing
    p2pnetsh.dll               6.1.7600.16385                 NetSh
    packager.dll               6.1.7601.18645               2
    panmap.dll                 6.1.7600.16385              PANOSE(tm) Font Mapper
    pautoenr.dll               6.1.7600.16385                
    pcaui.dll                  6.1.7600.16385                  
    pcwum.dll                  6.1.7600.16385              Performance Counters for Windows Native DLL
    pdh.dll                    6.1.7601.17514                  Windows
    pdhui.dll                  6.1.7601.17514                
    peerdist.dll               6.1.7600.16385                BranchCache
    peerdistsh.dll             6.1.7600.16385                BranchCache Netshell
    perfcentercpl.dll          6.1.7601.17514               
    perfctrs.dll               6.1.7600.16385               
    perfdisk.dll               6.1.7600.16385                  Windows
    perfnet.dll                6.1.7600.16385                   Windows
    perfos.dll                 6.1.7600.16385                  Windows
    perfproc.dll               6.1.7600.16385                   Windows
    perfts.dll                 6.1.7601.17514              Windows Remote Desktop Services Performance Objects
    photometadatahandler.dll   6.1.7600.16385              Photo Metadata Handler
    photowiz.dll               6.1.7601.17514                
    pid.dll                    6.1.7600.16385              Microsoft PID
    pidgenx.dll                6.1.7600.16385              Pid Generation
    pifmgr.dll                 6.1.7601.17514              Windows NT PIF Manager Icon Resources Library
    pku2u.dll                  6.1.7601.18658              Pku2u Security Package
    pla.dll                    6.1.7601.17514                 
    playsndsrv.dll             6.1.7600.16385               PlaySound
    pmcsnap.dll                6.1.7600.16385              pmcsnap dll
    pncrt.dll                  4.20.0.0                    
    pngfilt.dll                11.0.9600.16428             IE PNG plugin image decoder
    pnidui.dll                 6.1.7601.17514                
    pnpsetup.dll               6.1.7600.16385              Pnp installer for CMI
    pnrpnsp.dll                6.1.7600.16385                 PNRP
    polstore.dll               6.1.7600.16385              Policy Storage dll
    portabledeviceapi.dll      6.1.7601.17514               API    Windows
    portabledeviceclassextension.dll  6.1.7600.16385              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  6.1.7600.16385              Portable Device Connection API Components
    portabledevicestatus.dll   6.1.7601.17514                  Microsoft Windows
    portabledevicesyncprovider.dll  6.1.7601.17514                 Microsoft Windows
    portabledevicetypes.dll    6.1.7600.16385              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  6.1.7600.16385              PortableDevice WIA Compatibility Driver
    portabledevicewmdrm.dll    6.1.7600.16385              Windows Portable Device WMDRM Component
    pots.dll                   6.1.7600.16385               
    powercpl.dll               6.1.7601.17514                
    powrprof.dll               6.1.7600.16385              DLL     
    ppcsnap.dll                6.1.7600.16385              ppcsnap DLL
    presentationcffrasterizernative_v0300.dll  3.0.6920.5469               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  4.0.40305.0                 Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.4902               PresentationNative_v0300.dll
    prflbmsg.dll               6.1.7600.16385                  
    printui.dll                6.1.7601.17514                 
    prncache.dll               6.1.7601.17514              Print UI Cache
    prnfldr.dll                6.1.7601.17514              prnfldr dll
    prnntfy.dll                6.1.7600.16385              prnntfy DLL
    prntvpt.dll                6.1.7601.17514              Print Ticket Services Module
    profapi.dll                6.1.7600.16385              User Profile Basic API
    propsys.dll                7.0.7601.17514                 (Microsoft)
    provsvc.dll                6.1.7601.17514                Windows
    provthrd.dll               6.1.7600.16385              WMI Provider Thread & Log Library
    psapi.dll                  6.1.7600.16385              Process Status Helper
    psbase.dll                 6.1.7600.16385                
    pshed.dll                  6.1.7600.16385                ,   
    psisdecd.dll               6.6.7601.17669              Microsoft SI/PSI parser for MPEG2 based networks.
    pstorec.dll                6.1.7600.16385              Protected Storage COM interfaces
    pstorsvc.dll               6.1.7600.16385              Protected storage server
    puiapi.dll                 6.1.7600.16385               DLL puiapi
    puiobj.dll                 6.1.7601.17514               DLL  PrintUI
    pwrshplugin.dll            6.1.7600.16385              pwrshplugin.dll
    qagent.dll                 6.1.7601.17514                
    qasf.dll                   12.0.7601.19091             DirectShow ASF Support
    qcap.dll                   6.6.7601.17514                DirecxX DirectShow.
    qcliprov.dll               6.1.7601.17514               WMI   
    qdv.dll                    6.6.7601.17514                DirecxX DirectShow.
    qdvd.dll                   6.6.7601.19091              DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.6.7601.19091               DirectShow
    qedwipes.dll               6.6.7600.16385              DirectShow Editing SMPTE Wipes
    qmgrprxy.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    qshvhost.dll               6.1.7601.17514                SHV
    qsvrmgmt.dll               6.1.7601.17514                
    quartz.dll                 6.6.7601.19091                DirecxX DirectShow.
    query.dll                  6.1.7601.17514                  
    qutil.dll                  6.1.7601.17514                
    qwave.dll                  6.1.7600.16385              Windows NT
    raac.dll                   17.0.6.13                   RealAudio AAC Format -- the standard-compatible solution.
    racengn.dll                6.1.7601.17514                  
    racpldlg.dll               6.1.7600.16385                 
    radardt.dll                6.1.7600.16385                   Windows
    radarrs.dll                6.1.7600.16385                   Microsoft Windows
    rapidfire.dll              1.2.1.286                   AMD RapidFire
    rapidfireserver.dll        1.2.0.15                    AMD Rapid Fire Server
    rasadhlp.dll               6.1.7600.16385              Remote Access AutoDial Helper
    rasapi32.dll               6.1.7600.16385              Remote Access API
    rascfg.dll                 6.1.7600.16385                RAS
    raschap.dll                6.1.7601.17514                 PPP CHAP
    rasctrs.dll                6.1.7600.16385                     Windows NT
    rasdiag.dll                6.1.7600.16385                  RAS
    rasdlg.dll                 6.1.7600.16385              API     
    rasgcw.dll                 6.1.7600.16385                RAS
    rasman.dll                 6.1.7600.16385              Remote Access Connection Manager
    rasmm.dll                  6.1.7600.16385                RAS
    rasmontr.dll               6.1.7600.16385                RAS
    rasmxs.dll                 6.1.7600.16385              Remote Access Device DLL for modems, PADs and switches
    rasplap.dll                6.1.7600.16385                 RAS PLAP
    rasppp.dll                 6.1.7601.17514              Remote Access PPP
    rasser.dll                 6.1.7600.16385              Remote Access Media DLL for COM ports
    rastapi.dll                6.1.7601.17514              Remote Access TAPI Compliance Layer
    rastls.dll                 6.1.7601.18584                 PPP EAP-TLS
    rdpcore.dll                6.1.7601.17779              RDP Core DLL
    rdpd3d.dll                 6.1.7601.17514              RDP Direct3D Remoting DLL
    rdpencom.dll               6.1.7601.17514              RDPSRAPI COM Objects
    rdpendp.dll                6.1.7601.17514                 RDP
    rdpendp_winip.dll          6.2.9200.16398              RDP Audio Endpoint
    rdprefdrvapi.dll           6.1.7601.17514              Reflector Driver API
    rdvgumd32.dll              6.1.7601.17514                 ()
    rdvidcrl.dll               6.3.9600.16415              Remote Desktop Services Client for Microsoft Online Services
    reagent.dll                6.1.7601.17514               DLL   Microsoft Windows
    regapi.dll                 6.1.7601.17514              Registry Configuration APIs
    regctrl.dll                6.1.7600.16385              RegCtrl
    remotepg.dll               6.1.7601.17514              CPL-  
    resampledmo.dll            6.1.7601.19091              Windows Media Resampler
    resutils.dll               6.1.7601.17514              Microsoft Cluster Resource Utility DLL
    rgb9rast.dll               6.1.7600.16385              Microsoft Windows Operating System
    riched20.dll               5.31.23.1230                Rich Text Edit Control, v3.1
    riched32.dll               6.1.7601.17514              Wrapper Dll for Richedit 1.0
    rnr20.dll                  6.1.7600.16385              Windows Socket2 NameSpace DLL
    rpcdiag.dll                6.1.7600.16385              RPC Diagnostics
    rpchttp.dll                6.1.7601.17514              RPC HTTP DLL
    rpcndfp.dll                1.0.0.1                        RPC NDF
    rpcns4.dll                 6.1.7600.16385                    (RPC)
    rpcnsh.dll                 6.1.7600.16385                RPC Netshell
    rpcrt4.dll                 6.1.7601.19160                 
    rpcrtremote.dll            6.1.7601.17514              Remote RPC Extension
    rsaenh.dll                 6.1.7600.16385              Microsoft Enhanced Cryptographic Provider
    rshx32.dll                 6.1.7600.16385                
    rstrtmgr.dll               6.1.7600.16385               
    rtffilt.dll                2008.0.7600.16385            RTF
    rtm.dll                    6.1.7600.16385                
    rtutils.dll                6.1.7601.17514              Routing Utilities
    rv10.dll                   17.0.6.13                   RealVideo 1.0
    rv20.dll                   16.0.3.51                   RealVideo G2
    rv30.dll                   17.0.6.13                   RealVideo
    rv40.dll                   17.0.6.13                   RealVideo
    samcli.dll                 6.1.7601.17514              Security Accounts Manager Client DLL
    samlib.dll                 6.1.7600.16385              SAM Library DLL
    sampleres.dll              6.1.7600.16385               (Microsoft)
    sas.dll                    6.1.7600.16385              WinLogon Software SAS Library
    sbe.dll                    6.6.7601.17528              DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.7600.16385             Stream Buffer IO DLL
    sberes.dll                 6.6.7600.16385                  DirectShow.
    scansetting.dll            6.1.7601.17514                    Microsoft Windows(TM)
    scarddlg.dll               6.1.7600.16385              SCardDlg -   -
    scecli.dll                 6.1.7601.17514                 
    scesrv.dll                 6.1.7601.18686                
    schannel.dll               6.1.7601.19160              TLS / SSL Security Provider
    schedcli.dll               6.1.7601.17514              Scheduler Service Client DLL
    scksp.dll                  6.1.7600.16385              Microsoft Smart Card Key Storage Provider
    scripto.dll                6.6.7600.16385              Microsoft ScriptO
    scrobj.dll                 5.8.7600.16385              Windows  Script Component Runtime
    scrptadm.dll               6.1.7601.17514                
    scrrun.dll                 5.8.7601.18283              Microsoft  Script Runtime
    sdiageng.dll               6.1.7600.16385                 
    sdiagprv.dll               6.1.7600.16385              API    Windows
    sdohlp.dll                 6.1.7600.16385                 SDO NPS
    searchfolder.dll           6.1.7601.17514              SearchFolder
    sechost.dll                6.1.7600.16385              Host for SCM/SDDL/LSA Lookup APIs
    secproc.dll                6.1.7601.18332              Windows Rights Management Desktop Security Processor
    secproc_isv.dll            6.1.7601.18332              Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            6.1.7601.18332              Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        6.1.7601.18332              Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                6.1.7601.19160              Security Support Provider Interface
    security.dll               6.1.7600.16385              Security Support Provider Interface
    sendmail.dll               6.1.7600.16385               
    sens.dll                   6.1.7600.16385                   (SENS)
    sensapi.dll                6.1.7600.16385              SENS Connectivity API DLL
    sensorsapi.dll             6.1.7600.16385              Sensor API
    sensorscpl.dll             6.1.7601.17514                "    "
    serialui.dll               6.1.7600.16385                
    serwvdrv.dll               6.1.7600.16385                Unimodem
    sessenv.dll                6.1.7601.17514                   
    setupapi.dll               6.1.7601.17514              Windows Setup API
    setupcln.dll               6.1.7601.17514                
    sfc.dll                    6.1.7600.16385              Windows File Protection
    sfc_os.dll                 6.1.7600.16385              Windows File Protection
    sfcom.dll                  3.0.0.11                    SFCOM.DLL
    shacct.dll                 6.1.7601.17514              Shell Accounts Classes
    shdocvw.dll                6.1.7601.18222                    
    shell32.dll                6.1.7601.18952                 Windows
    shellstyle.dll             6.1.7600.16385              Windows Shell Style Resource Dll
    shfolder.dll               6.1.7600.16385              Shell Folder Service
    shgina.dll                 6.1.7601.17514              Windows Shell User Logon
    shimeng.dll                6.1.7601.19050              Shim Engine DLL
    shimgvw.dll                6.1.7601.17514               
    shlwapi.dll                6.1.7601.17514                 
    shpafact.dll               6.1.7600.16385              Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                6.1.7601.17514              Shell setup helper
    shsvcs.dll                 6.1.7601.17514               DLL   Windows
    shunimpl.dll               6.1.7601.17514              Windows Shell Obsolete APIs
    shwebsvc.dll               6.1.7601.17514              -  Windows
    signdrv.dll                6.1.7600.16385              WMI provider for Signed Drivers
    sipr.dll                   17.0.6.13                   ACELP-NET Voice Codec for RealAudio(tm)
    sisbkup.dll                6.1.7601.17514              Single-Instance Store Backup Support Functions
    slc.dll                    6.1.7600.16385              Software Licensing Client DLL
    slcext.dll                 6.1.7600.16385              Software Licensing Client Extension Dll
    slwga.dll                  6.1.7601.17514              Software Licensing WGA API
    smackw32.dll               3.0.0.0                     Smacker Video Technology
    smartcardcredentialprovider.dll  6.1.7601.18276                 - Windows
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    sndvolsso.dll              6.1.7601.17514               SCA 
    snmpapi.dll                6.1.7600.16385              SNMP Utility Library
    softkbd.dll                6.1.7600.16385                  
    softpub.dll                6.1.7600.16385              Softpub Forwarder DLL
    sortserver2003compat.dll   6.1.7600.16385              Sort Version Server 2003
    sortwindows6compat.dll     6.1.7600.16385              Sort Version Windows 6.0
    spbcd.dll                  6.1.7601.17514              BCD Sysprep Plugin
    spfileq.dll                6.1.7600.16385              Windows SPFILEQ
    spinf.dll                  6.1.7600.16385              Windows SPINF
    spnet.dll                  6.1.7600.16385              Net Sysprep Plugin
    spopk.dll                  6.1.7601.17514              OPK Sysprep Plugin
    spp.dll                    6.1.7601.17514                  Microsoft Windows
    sppc.dll                   6.1.7601.17514              Software Licensing Client DLL
    sppcc.dll                  6.1.7600.16385                  
    sppcext.dll                6.1.7600.16385              Software Protection Platform Client Extension Dll
    sppcomapi.dll              6.1.7601.17514                 
    sppcommdlg.dll             6.1.7600.16385              API     
    sppinst.dll                6.1.7601.17514              SPP CMI Installer Plug-in DLL
    sppwmi.dll                 6.1.7600.16385              Software Protection Platform WMI provider
    spwinsat.dll               6.1.7600.16385              WinSAT Sysprep Plugin
    spwizeng.dll               6.1.7601.17514              Setup Wizard Framework
    spwizimg.dll               6.1.7600.16385              Setup Wizard Framework Resources
    spwizres.dll               6.1.7601.17514                 
    spwmp.dll                  6.1.7601.19148              Windows Media Player System Preparation DLL
    sqlceoledb30.dll           3.0.7600.0                  Microsoft SQL Mobile
    sqlceqp30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqlcese30.dll              3.0.7601.0                  Microsoft SQL Mobile
    sqloledb.dll               6.1.7601.17514              OLE DB Provider for SQL Server
    sqloledb.dll               6.1.7601.17514              OLE DB Provider for SQL Server
    sqlsrv32.dll               6.1.7601.17514              SQL Server ODBC Driver
    sqlunirl.dll               2000.80.728.0               String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 1999.10.20.0                Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 1999.10.20.0                Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                6.1.7600.16385              XML extensions for SQL Server
    sqlxmlx.dll                6.1.7600.16385              XML extensions for SQL Server
    sqmapi.dll                 6.1.7601.17514              SQM Client
    srchadmin.dll              7.0.7601.17514               
    srclient.dll               6.1.7601.19160              Microsoft Windows System Restore Client Library
    srhelper.dll               6.1.7600.16385              Microsoft Windows driver and windows update enumeration library
    srpuxnativesnapin.dll      6.1.7600.16385                     
    srvcli.dll                 6.1.7601.17514              Server Service Client DLL
    sscore.dll                 6.1.7601.17514               DLL-  
    ssdpapi.dll                6.1.7600.16385              SSDP Client API DLL
    ssleay32.dll               1.0.1.5                     OpenSSL Shared Library
    sspicli.dll                6.1.7601.19160              Security Support Provider Interface
    ssshim.dll                 6.1.7600.16385              Windows Componentization Platform Servicing API
    stclient.dll               2001.12.8530.16385          COM+ Configuration Catalog Client
    sti.dll                    6.1.7600.16385                   
    stobject.dll               6.1.7601.17514                 Systray
    storage.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    storagecontexthandler.dll  6.1.7600.16385                   
    storprop.dll               6.1.7600.16385                  
    structuredquery.dll        7.0.7601.17514              Structured Query
    sud.dll                    6.1.7601.17514                SUD
    sxproxy.dll                6.1.7600.16385                  Microsoft Windows
    sxs.dll                    6.1.7601.17514              Fusion 2.5
    sxshared.dll               6.1.7600.16385              Microsoft Windows SX Shared Library
    sxsstore.dll               6.1.7600.16385              Sxs Store DLL
    synccenter.dll             6.1.7601.17514                
    synceng.dll                6.1.7601.17959              Windows Briefcase Engine
    synchostps.dll             6.1.7600.16385              Proxystub for sync host
    syncinfrastructure.dll     6.1.7600.16385                Microsoft Windows.
    syncinfrastructureps.dll   6.1.7600.16385              Microsoft Windows sync infrastructure proxy stub.
    syncreg.dll                2007.94.7600.16385          Microsoft Synchronization Framework Registration
    syncui.dll                 6.1.7601.17514               Windows
    syssetup.dll               6.1.7601.17514              Windows NT System Setup
    systemcpl.dll              6.1.7601.17514              CPL 
    t2embed.dll                6.1.7601.17514              Microsoft T2Embed Font Embedding
    tapi3.dll                  6.1.7600.16385              Microsoft TAPI3
    tapi32.dll                 6.1.7600.16385               API  Microsoft Windows
    tapimigplugin.dll          6.1.7600.16385              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               6.1.7600.16385              Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                6.1.7601.17514                 Microsoft Windows
    tapisysprep.dll            6.1.7600.16385              Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 6.1.7600.16385               DLL   Microsoft Windows
    taskcomp.dll               6.1.7601.17514                  
    taskschd.dll               6.1.7601.17514              Task Scheduler COM API
    taskschdps.dll             6.1.7600.16385              Task Scheduler Interfaces Proxy
    tbs.dll                    6.1.7600.16385              TBS
    tcpipcfg.dll               6.1.7601.17514                
    tcpmonui.dll               6.1.7600.16385                  TCP/IP
    tdh.dll                    6.1.7600.16385                 
    termmgr.dll                6.1.7601.17514              Microsoft TAPI3 Terminal Manager
    thawbrkr.dll               6.1.7600.16385              Thai Word Breaker
    themecpl.dll               6.1.7601.17514              CPL 
    themeui.dll                6.1.7601.17514              API   Windows
    thumbcache.dll             6.1.7601.17514                
    timedatemuicallback.dll    6.1.7600.16385              Time Date Control UI Language Change plugin
    tlscsp.dll                 6.1.7601.17514              Microsoft Remote Desktop Services Cryptographic Utility
    tpmcompc.dll               6.1.7600.16385                
    tquery.dll                 7.0.7601.17610              tquery.dll
    traffic.dll                6.1.7600.16385              Microsoft Traffic Control 1.0 DLL
    trapi.dll                  6.1.7601.17514              Microsoft Narrator Text Renderer
    tsbyuv.dll                 6.1.7601.17514              Toshiba Video Codec
    tschannel.dll              6.1.7600.16385              Task Scheduler Proxy
    tsgqec.dll                 6.3.9600.16415                      
    tsmf.dll                   6.1.7601.17514                MF    
    tspkg.dll                  6.1.7601.19160              Web Service Security Package
    tsworkspace.dll            6.1.7601.18546                      RemoteApp
    tvratings.dll              6.6.7600.16385              Module for managing TV ratings
    twext.dll                  6.1.7601.17514              :  
    txflog.dll                 2001.12.8530.16385          COM+
    txfw32.dll                 6.1.7600.16385              TxF Win32 DLL
    typelib.dll                2.10.3029.1                 OLE 2.1 16/32 Interoperability Library
    tzres.dll                  6.1.7601.19055               DLL   
    ubpm.dll                   6.1.7601.18741               DLL    
    ucmhc.dll                  6.1.7600.16385                 UCM
    ucrtbase.dll               10.0.10586.9                Microsoft C Runtime Library
    udhisapi.dll               6.1.7600.16385              UPnP Device Host ISAPI Extension
    uexfat.dll                 6.1.7600.16385              eXfat Utility DLL
    ufat.dll                   6.1.7600.16385              FAT Utility DLL
    uianimation.dll            6.2.9200.16492              Windows Animation Manager
    uiautomationcore.dll       7.0.0.0                        Microsoft UI
    uicom.dll                  6.1.7600.16385              Add/Remove Modems
    uiribbon.dll               6.1.7601.17514                Windows
    uiribbonres.dll            6.1.7601.17514              Windows Ribbon Framework Resources
    ulib.dll                   6.1.7600.16385              DLL   
    umdmxfrm.dll               6.1.7600.16385              Unimodem Tranform Module
    unimdmat.dll               6.1.7601.17514              - AT   Unimodem
    uniplat.dll                6.1.7600.16385              Unimodem AT Mini Driver Platform Driver for Windows NT
    untfs.dll                  6.1.7601.17514              NTFS Utility DLL
    upnp.dll                   6.1.7601.17514              API   UPnP
    upnphost.dll               6.1.7600.16385                PNP-
    ureg.dll                   6.1.7600.16385              Registry Utility DLL
    url.dll                    11.0.9600.16428             Internet Shortcut Shell Extension DLL
    urlmon.dll                 11.0.9600.18231              OLE32  Win32
    usbceip.dll                6.1.7600.16385               USBCEIP
    usbperf.dll                6.1.7600.16385               DLL   USB
    usbui.dll                  6.1.7600.16385              USB UI Dll
    user32.dll                 6.1.7601.19061                 USER API Windows
    useraccountcontrolsettings.dll  6.1.7601.17514                  
    usercpl.dll                6.1.7601.17514                
    userenv.dll                6.1.7601.17514              Userenv
    usp10.dll                  1.626.7601.19054            Uniscribe Unicode script processor
    utildll.dll                6.1.7601.17514                WinStation
    utv_core.dll                                           
    utv_dmo.dll                1.0.0.1                     TODO: <???????>
    utv_mft.dll                1.0.0.1                     TODO: <???????>
    utv_vcm.dll                                            
    uudf.dll                   6.1.7600.16385              UDF Utility DLL
    uxinit.dll                 6.1.7600.16385              Windows User Experience Session Initialization Dll
    uxlib.dll                  6.1.7601.17514              Setup Wizard Framework
    uxlibres.dll               6.1.7600.16385              UXLib Resources
    uxtheme.dll                6.1.7600.16385                UxTheme (Microsoft)
    van.dll                    6.1.7601.17514                
    vault.dll                  6.1.7601.17514                -  Windows
    vaultcli.dll               6.1.7600.16385              Credential Vault Client Library
    vb40016.dll                4.0.24.22                   Visual Basic 4.0 runtime library
    vb40032.dll                4.0.29.24                   Visual Basic 4.0 runtime library
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbrun100.dll                                           
    vbrun200.dll               2.0.9.8                     Visual Basic 2.0 runtime library
    vbrun300.dll               3.0.5.38                    Visual Basic 3.0 runtime library
    vbscript.dll               5.8.9600.18231              Microsoft  VBScript
    vcamp110.dll               11.0.51106.1                Microsoft C++ AMP Runtime
    vcamp120.dll               12.0.21005.1                Microsoft C++ AMP Runtime
    vcamp140.dll               14.23.27820.0               Microsoft C++ AMP Runtime
    vccorlib110.dll            11.0.51106.1                Microsoft  VC WinRT core library
    vccorlib120.dll            12.0.21005.1                Microsoft  VC WinRT core library
    vccorlib140.dll            14.23.27820.0               Microsoft  VC WinRT core library
    vcomp100.dll               10.0.40219.325              Microsoft C/C++ OpenMP Runtime
    vcomp110.dll               11.0.51106.1                Microsoft C/C++ OpenMP Runtime
    vcomp120.dll               12.0.21005.1                Microsoft C/C++ OpenMP Runtime
    vcomp140.dll               14.23.27820.0               Microsoft C/C++ OpenMP Runtime
    vcruntime140.dll           14.23.27820.0               Microsoft C Runtime Library
    vdmdbg.dll                 6.1.7600.16385              VDMDBG.DLL
    vds_ps.dll                 6.1.7600.16385              Microsoft Virtual Disk Service proxy/stub
    vdsbas.dll                 6.1.7601.17514                  
    vdsdyn.dll                 6.1.7600.16385                  VDS,  2.1.0.1
    vdsvd.dll                  6.1.7600.16385              VDS Virtual Disk Provider, Version 1.0
    verifier.dll               6.1.7600.16385              Standard application verifier provider dll
    version.dll                6.1.7600.16385              Version Checking and File Installation Libraries
    vfpodbc.dll                1.0.2.0                     vfpodbc
    vfwwdm32.dll               6.1.7601.17514               VfW MM Driver    WDM-
    vidreszr.dll               6.1.7601.19091              Windows Media Resizer
    virtdisk.dll               6.1.7600.16385              Virtual Disk API DLL
    vmnc.dll                   7.1.2.14247                 VMware Movie decoder
    vp8vfw.dll                 1.2.0.0                     Google VP8 VFW Video Codec
    vpnikeapi.dll              6.1.7601.17514              VPN IKE API's
    vss_ps.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 6.1.7601.17514              Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               6.1.7600.16385                    Microsoft
    vulkan-1.dll               1.2.131.2                   Vulkan Loader
    vulkan-1-999-0-0-0.dll     1.2.131.2                   Vulkan Loader
    w32topl.dll                6.1.7600.16385              Windows NT Topology Maintenance Tool
    wab32.dll                  6.1.7601.17699              Microsoft (R) Contacts DLL
    wab32.dll                  6.1.7601.17699              Microsoft (R) Contacts DLL
    wab32res.dll               6.1.7600.16385               Microsoft (R) DLL
    wab32res.dll               6.1.7600.16385               Microsoft (R) DLL
    wabsyncprovider.dll        6.1.7600.16385                 Microsoft Windows
    wavemsp.dll                6.1.7601.17514              Microsoft Wave MSP
    wbemcomn.dll               6.1.7601.17514              WMI
    wcnapi.dll                 6.1.7600.16385              Windows Connect Now - API Helper DLL
    wcncsvc.dll                6.1.7601.17514                Windows -   
    wcneapauthproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP Authenticator Proxy
    wcneappeerproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP PEER Proxy
    wcnwiz.dll                 6.1.7600.16385                Windows Connect Now
    wcspluginservice.dll       6.1.7600.16385               DLL WcsPlugInService
    wdc.dll                    6.1.7601.17514               
    wdi.dll                    6.1.7600.16385                Windows
    wdigest.dll                6.1.7601.19160              Microsoft Digest Access
    wdscore.dll                6.1.7601.17514              Panther Engine Module
    webcheck.dll               11.0.9600.18231              -
    webclnt.dll                6.1.7601.18912               DLL - DAV
    webio.dll                  6.1.7601.17725              API    
    webservices.dll            6.1.7601.17514                - Windows
    wecapi.dll                 6.1.7600.16385              Event Collector Configuration API
    wer.dll                    6.1.7601.18381                  Windows
    werdiagcontroller.dll      6.1.7600.16385              WER Diagnostic Controller
    werui.dll                  6.1.7600.16385               DLL      Windows
    wevtapi.dll                6.1.7600.16385              API    
    wevtfwd.dll                6.1.7600.16385              WS-Management Event Forwarding Plug-in
    wfapigp.dll                6.1.7600.16385              Windows Firewall GPO Helper dll
    wfhc.dll                   6.1.7600.16385               Windows.   
    whealogr.dll               6.1.7600.16385                WHEA
    whhelper.dll               6.1.7600.16385              DLL     winHttp
    wiaaut.dll                 6.1.7600.16385               WIA-
    wiadefui.dll               6.1.7601.17514                  WIA
    wiadss.dll                 6.1.7600.16385               WIA -  TWAIN
    wiaextensionhost64.dll     6.1.7600.16385              WIA Extension Host for thunking APIs from 32-bit to 64-bit process
    wiascanprofiles.dll        6.1.7600.16385              Microsoft Windows ScanProfiles
    wiashext.dll               6.1.7600.16385                     
    wiatrace.dll               6.1.7600.16385              WIA Tracing
    wiavideo.dll               6.1.7601.17514              WIA Video
    wimgapi.dll                6.1.7601.17514               Windows Imaging
    win32spl.dll               6.1.7601.18142                    
    winbio.dll                 6.1.7600.16385              API   Windows
    winbrand.dll               6.1.7600.16385              Windows Branding Resources
    wincredprovider.dll        6.1.7601.18409               DLL wincredprovider
    windowscodecs.dll          6.2.9200.17251              Microsoft Windows Codecs Library
    windowscodecsext.dll       6.2.9200.16492              Microsoft Windows Codecs Extended Library
    winfax.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    winhttp.dll                6.1.7601.17514               HTTP Windows
    wininet.dll                11.0.9600.18231                Win32
    winipsec.dll               6.1.7600.16385              Windows IPsec SPD Client DLL
    winmm.dll                  6.1.7601.17514              MCI API DLL
    winnsi.dll                 6.1.7600.16385              Network Store Information RPC interface
    winrnr.dll                 6.1.7600.16385              LDAP RnR Provider DLL
    winrscmd.dll               6.1.7600.16385              remtsvc
    winrsmgr.dll               6.1.7600.16385              WSMan Shell API
    winrssrv.dll               6.1.7600.16385              winrssrv
    winsatapi.dll              6.1.7601.17514              Windows System Assessment Tool API
    winscard.dll               6.1.7601.17514              API - (Microsoft)
    winshfhc.dll               6.1.7600.16385              File Risk Estimation
    winsockhc.dll              6.1.7600.16385                   Winsock
    winsrpc.dll                6.1.7600.16385              WINS RPC LIBRARY
    winsta.dll                 6.1.7601.18540              Winstation Library
    winsync.dll                2007.94.7600.16385          Synchronization Framework
    winsyncmetastore.dll       2007.94.7600.16385          Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.7600.16385          Windows Synchronization Provider Framework
    wintrust.dll               6.1.7601.18839              Microsoft Trust Verification APIs
    winusb.dll                 6.1.7600.16385              Windows USB Driver User Library
    wkscli.dll                 6.1.7601.17514              Workstation Service Client DLL
    wksprtps.dll               6.3.9600.16415              WorkspaceRuntime ProxyStub DLL
    wlanapi.dll                6.1.7600.16385              Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                6.1.7600.16385               DLL    Netsh  WLAN
    wlanconn.dll               6.1.7600.16385                Dot11
    wlandlg.dll                6.1.7600.16385                   
    wlangpui.dll               6.1.7601.17514               "   "
    wlanhlp.dll                6.1.7600.16385              Windows Wireless LAN 802.11 Client Side Helper API
    wlaninst.dll               6.1.7600.16385              Windows NET Device Class Co-Installer for Wireless LAN
    wlanmm.dll                 6.1.7600.16385                Dot11   
    wlanmsm.dll                6.1.7601.17514              Windows Wireless LAN 802.11 MSM DLL
    wlanpref.dll               6.1.7601.17514                
    wlansec.dll                6.1.7600.16385              Windows Wireless LAN 802.11 MSM Security Module DLL
    wlanui.dll                 6.1.7601.17514                 
    wlanutil.dll               6.1.7600.16385               DLL     Windows   802.11
    wldap32.dll                6.1.7601.17514              Win32 LDAP API DLL
    wlgpclnt.dll               6.1.7600.16385                 802.11
    wls0wndh.dll               6.1.7600.16385              Session0 Viewer Window Hook DLL
    wmadmod.dll                6.1.7601.19091              Windows Media Audio Decoder
    wmadmoe.dll                6.1.7601.19091              Windows Media Audio 10 Encoder/Transcoder
    wmasf.dll                  12.0.7600.16385             Windows Media ASF DLL
    wmcodecdspps.dll           6.1.7600.16385              Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.7600.16385             Windows Media Device Manager Logger
    wmdmps.dll                 12.0.7600.16385             Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               12.0.7601.17514             Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               12.0.7601.17514             Windows Media DRM for Network Devices DLL
    wmdrmsdk.dll               11.0.7601.18741             Windows Media DRM SDK DLL
    wmerror.dll                12.0.7600.16385               Windows Media ()
    wmi.dll                    6.1.7601.17787              WMI DC and DP functionality
    wmidx.dll                  12.0.7600.16385             Windows Media Indexer DLL
    wmiprop.dll                6.1.7600.16385                  WDM
    wmnetmgr.dll               12.0.7601.17514             Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.7601.19148             Windows Media Player
    wmpcm.dll                  12.0.7600.16385             Windows Media Player Compositing Mixer
    wmpdui.dll                 12.0.7600.16385             Windows DirectUser Engine
    wmpdxm.dll                 12.0.7601.17514             Windows Media Player Extension
    wmpeffects.dll             12.0.7601.17514             Windows Media Player Effects
    wmpencen.dll               12.0.7601.17514             Windows Media Player Encoding Module
    wmphoto.dll                6.2.9200.17254               Windows Media
    wmploc.dll                 12.0.7601.19148               Windows Media
    wmpmde.dll                 12.0.7601.19091             WMPMDE DLL
    wmpps.dll                  12.0.7601.17514             Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.7601.17514                Windows Media
    wmpsrcwp.dll               12.0.7601.17514             WMPSrcWp Module
    wmsgapi.dll                6.1.7600.16385              WinLogon IPC Client
    wmspdmod.dll               6.1.7601.19091              Windows Media Audio Voice Decoder
    wmspdmoe.dll               6.1.7601.19091              Windows Media Audio Voice Encoder
    wmvcore.dll                12.0.7601.17514             Windows Media Playback/Authoring DLL
    wmvdecod.dll               6.1.7601.19091              Windows Media Video Decoder
    wmvdspa.dll                6.1.7600.16385              Windows Media Video DSP Components - Advanced
    wmvencod.dll               6.1.7601.19091              Windows Media Video 9 Encoder
    wmvsdecd.dll               6.1.7601.19091              Windows Media Screen Decoder
    wmvsencd.dll               6.1.7601.19091              Windows Media Screen Encoder
    wmvxencd.dll               6.1.7601.19091              Windows Media Video Encoder
    wow32.dll                  6.1.7601.19160              Wow32
    wpc.dll                    1.0.0.1                        
    wpcao.dll                  6.1.7600.16385                WPC
    wpcsvc.dll                 1.0.0.1                         Windows
    wpdshext.dll               6.1.7601.18738                  
    wpdshserviceobj.dll        6.1.7601.17514              Windows Portable Device Shell Service Object
    wpdsp.dll                  6.1.7601.17514              WMDM Service Provider for Windows Portable Devices
    wpdwcn.dll                 6.1.7601.17514                    WCN
    wrap_oal.dll               2.2.0.7                     OpenAL32
    ws2_32.dll                 6.1.7601.17514              32-  Windows Socket 2.0
    ws2help.dll                6.1.7600.16385              Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 6.1.7601.17514              Windows Security Center API
    wscinterop.dll             6.1.7600.16385              Windows Health Center WSC Interop
    wscisvif.dll               6.1.7600.16385              Windows Security Center ISV API
    wscmisetup.dll             6.1.7600.16385              Installers for Winsock Transport and Name Space Providers
    wscproxystub.dll           6.1.7600.16385              Windows Security Center ISV Proxy Stub
    wsdapi.dll                 6.1.7601.17514              -   DLL API- 
    wsdchngr.dll               6.1.7601.17514              WSD Challenge Component
    wsecedit.dll               6.1.7600.16385                 
    wshbth.dll                 6.1.7601.17514              Windows Sockets Helper DLL
    wshcon.dll                 5.8.7600.16385              Microsoft  Windows Script Controller
    wshelper.dll               6.1.7600.16385               DLL    Winsock Net
    wshext.dll                 5.8.7600.16385              Microsoft  Shell Extension for Windows Script Host
    wship6.dll                 6.1.7600.16385               DLL  Winsock2 (TL/IPv6)
    wshirda.dll                6.1.7601.17514              Windows Sockets Helper DLL
    wshqos.dll                 6.1.7600.16385               DLL   QoS Winsock2
    wshrm.dll                  6.1.7601.19055                DLL   Windows  PGM
    wshtcpip.dll               6.1.7600.16385               DLL   Winsock2 (TL/IPv4)
    wsmanmigrationplugin.dll   6.1.7601.18619              WinRM Migration Plugin
    wsmauto.dll                6.1.7601.18619              WSMAN Automation
    wsmplpxy.dll               6.1.7600.16385              wsmplpxy
    wsmres.dll                 6.1.7600.16385               DLL  WSMan
    wsmsvc.dll                 6.1.7601.18619               WSMan
    wsmwmipl.dll               6.1.7601.18619              WSMAN WMI Provider
    wsnmp32.dll                6.1.7601.17514              Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                6.1.7600.16385              Windows Socket 32-Bit DLL
    wtsapi32.dll               6.1.7601.17514              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  7.6.7601.19161              API    Windows
    wudriver.dll               7.6.7601.19161              Windows Update WUDriver Stub
    wups.dll                   7.6.7601.19161              Windows Update client proxy stub
    wuwebv.dll                 7.6.7601.19161              Windows Update Vista Web Control
    wvc.dll                    6.1.7601.17514              Windows Visual Components
    wwanapi.dll                6.1.7600.16385              Mbnapi
    wwapi.dll                  8.1.2.0                     WWAN API
    wzcdlg.dll                 6.1.7600.16385              Windows Connect Now - Flash Config Enrollee
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput9_1_0.dll            6.1.7600.16385                XNA
    xmlfilter.dll              2008.0.7600.16385            XML
    xmllite.dll                1.3.1001.0                  Microsoft XmlLite Library
    xmlprovi.dll               6.1.7600.16385              Network Provisioning Service Client API
    xolehlp.dll                2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsfilt.dll                6.1.7600.16385              XML Paper Specification Document IFilter
    xpsgdiconverter.dll        6.2.9200.16492              XPS to GDI Converter
    xpsprint.dll               6.2.9200.16492              XPS Printing DLL
    xpsrasterservice.dll       6.1.7601.17514              XPS Rasterization Service Component
    xpsservices.dll            6.1.7601.17514              Xps Object Model in memory creation and deserialization
    xpsshhdr.dll               6.1.7600.16385              Package Document Shell Extension Handler
    xpssvcs.dll                6.1.7600.16385              Native Code Xps Services Library
    xvidcore.dll                                           
    xvidvfw.dll                                            
    xwizards.dll               6.1.7600.16385                 
    xwreg.dll                  6.1.7600.16385              Extensible Wizard Registration Manager Module
    xwtpdui.dll                6.1.7600.16385                   DUI
    xwtpw32.dll                6.1.7600.16385                   Win32
    zipfldr.dll                6.1.7601.17514               ZIP-


--------[  ]-------------------------------------------------------------------------------------------------

  [ Certificate Authorities / COMODO RSA Certification Authority ]

     :
                                                  V3
                                         SHA384 RSA  (1.2.840.113549.1.1.12)
                                           22 DE 84 FC A2 70 D7 AB 8E F3 49 EB 56 EE 66 27
                                            30.05.2000 - 30.05.2020
      MD5 Hash                                          1EDAF9AE99CE2920667D0E9A8B3F8C9C
      SHA1 Hash                                         F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0

     :
                                                     AddTrust External CA Root
                                             AddTrust AB
                                           AddTrust External TTP Network
                                                  Sweden

     :
                                                     COMODO RSA Certification Authority
                                             COMODO CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / COMODO RSA Domain Validation Secure Server CA ]

     :
                                                  V3
                                         SHA384 RSA  (1.2.840.113549.1.1.12)
                                           07 8C 7C A3 DB 6E 8A 14 6C 36 75 D9 EA 6E 2E 2B
                                            12.02.2014 - 12.02.2029
      MD5 Hash                                          83E10465B722EF33FF0B6F535E8D996B
      SHA1 Hash                                         339CDD57CFD5B141169B615FF31428782D1DA639

     :
                                                     COMODO RSA Certification Authority
                                             COMODO CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

     :
                                                     COMODO RSA Domain Validation Secure Server CA
                                             COMODO CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / COMODO RSA Extended Validation Code Signing CA ]

     :
                                                  V3
                                         SHA384 RSA  (1.2.840.113549.1.1.12)
                                           E1 45 E1 5F 3F 84 DD E3 06 04 AE 02 EB 72 D4 6D
                                            03.12.2014 - 03.12.2029
      MD5 Hash                                          FDBAD423138703D215B830D95243D0AF
      SHA1 Hash                                         351A78EBC1B4BB6DC366728D334231ABA9AE3EA7

     :
                                                     COMODO RSA Certification Authority
                                             COMODO CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

     :
                                                     COMODO RSA Extended Validation Code Signing CA
                                             COMODO CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / GlobalSign RSA DV SSL CA 2018 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           9E 9F 66 D4 A5 43 1B E7 2D 22 5F EE 01
                                            21.11.2018 - 21.11.2028
      MD5 Hash                                          58BEC6C6284DB2EA1A8ACA560691FF0F
      SHA1 Hash                                         A416002331A4E0C8C53D94AC1E0234723D8BDE97

     :
                                                     GlobalSign
                                             GlobalSign
                                           GlobalSign Root CA - R3

     :
                                                     GlobalSign RSA DV SSL CA 2018
                                             GlobalSign nv-sa
                                                  Belgium

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / Go Daddy Secure Certificate Authority - G2 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           07
                                            03.05.2011 - 03.05.2031
      MD5 Hash                                          96C25031BC0DC35CFBA723731E1B4140
      SHA1 Hash                                         27AC9369FAF25207BB2627CEFACCBE4EF9C319B8

     :
                                                     Go Daddy Root Certificate Authority - G2
                                             GoDaddy.com, Inc.
                                                  United States
                                         Scottsdale
      /                                     Arizona

     :
                                                     Go Daddy Secure Certificate Authority - G2
                                             GoDaddy.com, Inc.
                                           http://certs.godaddy.com/repository/
                                                  United States
                                         Scottsdale
      /                                     Arizona

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / Let's Encrypt Authority X3 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           08 A7 EC 85 0B 6A 73 85 53 01 00 00 42 41 01 0A
                                            17.03.2016 - 17.03.2021
      MD5 Hash                                          B15409274F54AD8F023D3B85A5ECEC5D
      SHA1 Hash                                         E6A3B45B062D509B3382282D196EFE97D5956CCB

     :
                                                     DST Root CA X3
                                             Digital Signature Trust Co.

     :
                                                     Let's Encrypt Authority X3
                                             Let's Encrypt
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / Microsoft Windows Hardware Compatibility ]

     :
                                                  V3
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           A0 69 FE 8F 9A 3F D1 11 8B 19
                                            01.10.1997 - 31.12.2002
      MD5 Hash                                          09C254BDE4EA50F26D1497F29C51AF6D
      SHA1 Hash                                         109F1CAED645BB78B3EA2B94C0697C740733031C

     :
                                                     Microsoft Root Authority
                                           Copyright (c) 1997 Microsoft Corp.
                                           Microsoft Corporation

     :
                                                     Microsoft Windows Hardware Compatibility
                                           Copyright (c) 1997 Microsoft Corp.
                                           Microsoft Windows Hardware Compatibility Intermediate CA
                                           Microsoft Corporation

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / Root Agency ]

     :
                                                  V3
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           F4 35 5C AA D4 B8 CF 11 8A 64 00 AA 00 6C 37 06
                                            29.05.1996 - 01.01.2040
      MD5 Hash                                          C0A723F0DA35026B21EDB17597F1D470
      SHA1 Hash                                         FEE449EE0E3965A5246F000E87FDE2A065FD89D4

     :
                                                     Root Agency

     :
                                                     Root Agency

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / Sectigo RSA Domain Validation Secure Server CA ]

     :
                                                  V3
                                         SHA384 RSA  (1.2.840.113549.1.1.12)
                                           A7 0D 53 BC 0B 16 74 DB 11 BA 76 B4 26 51 5B 7D
                                            02.11.2018 - 01.01.2031
      MD5 Hash                                          ADAB5C4DF031FB9299F71ADA7E18F613
      SHA1 Hash                                         33E4E80807204C2B6182A3A14B591ACD25B5F0DB

     :
                                                     USERTrust RSA Certification Authority
                                             The USERTRUST Network
                                                  United States
                                         Jersey City
      /                                     New Jersey

     :
                                                     Sectigo RSA Domain Validation Secure Server CA
                                             Sectigo Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / Thawte RSA CA 2018 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           2B 70 E6 1A B2 04 21 6C 0D 7E 6F 19 EF 8A 5A 02
                                            06.11.2017 - 06.11.2027
      MD5 Hash                                          42672E72F86C9BA154608D36BCCD3C61
      SHA1 Hash                                         4DEEA7060D80BABF1643B4E0F0104C82995075B7

     :
                                                     DigiCert Global Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

     :
                                                     Thawte RSA CA 2018
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Certificate Authorities / USERTrust ECC Certification Authority ]

     :
                                                  V3
                                         SHA384 RSA  (1.2.840.113549.1.1.12)
                                           D5 99 3D 40 71 3E 95 EE 4F 52 F3 D1 86 B7 D8 76
                                            30.05.2000 - 30.05.2020
      MD5 Hash                                          8E56CA70EFFCF6A72ED57CAF205059FC
      SHA1 Hash                                         C01B8463C8619676BA102EEBF0C30CDCED9A942B

     :
                                                     AddTrust External CA Root
                                             AddTrust AB
                                           AddTrust External TTP Network
                                                  Sweden

     :
                                                     USERTrust ECC Certification Authority
                                             The USERTRUST Network
                                                  United States
                                         Jersey City
      /                                     New Jersey

      :
                                 1.2.840.10045.2.1

  [ Certificate Authorities / www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           8F 07 93 3F 23 98 60 92 0F 2F D0 B4 BA EB FC 46
                                            17.04.1997 - 25.10.2016
      MD5 Hash                                          ACD80EA27BB72CE700DC22724A5F1E92
      SHA1 Hash                                         D559A586669B08F46A30A133F8A9ED3D038E2EA8

     :
                                             VeriSign, Inc.
                                           Class 3 Public Primary Certification Authority
                                                  United States

     :
                                             VeriSign Trust Network
                                           VeriSign, Inc.
                                           VeriSign International Server CA - Class 3

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Baltimore CyberTrust Root ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           B9 00 00 02
                                            12.05.2000 - 13.05.2025
      MD5 Hash                                          ACB694A59C17E0D791529BB19706A6E4
      SHA1 Hash                                         D4DE20D05E66FC53FE1A50882C78DB2852CAE474

     :
                                                     Baltimore CyberTrust Root
                                             Baltimore
                                           CyberTrust
                                                  Ireland

     :
                                                     Baltimore CyberTrust Root
                                             Baltimore
                                           CyberTrust
                                                  Ireland

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Certum Trusted Network CA ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           C0 44 04
                                            22.10.2008 - 31.12.2029
      MD5 Hash                                          D5E98140C51869FC462C8975620FAA78
      SHA1 Hash                                         07E032E020B72C3F192F0628A2593A19A70F069E

     :
                                                     Certum Trusted Network CA
                                             Unizeto Technologies S.A.
                                           Certum Certification Authority
                                                  Poland

     :
                                                     Certum Trusted Network CA
                                             Unizeto Technologies S.A.
                                           Certum Certification Authority
                                                  Poland

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Certum ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           20 00 01
                                            11.06.2002 - 11.06.2027
      MD5 Hash                                          2C8F9F661D1890B147269D8E86828CA9
      SHA1 Hash                                         6252DC40F71143A22FDE9EF7348E064251B18118

     :
                                                     Certum CA
                                             Unizeto Sp. z o.o.
                                                  Poland

     :
                                                     Certum CA
                                             Unizeto Sp. z o.o.
                                                  Poland

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / DigiCert Baltimore Root ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           B9 00 00 02
                                            12.05.2000 - 13.05.2025
      MD5 Hash                                          ACB694A59C17E0D791529BB19706A6E4
      SHA1 Hash                                         D4DE20D05E66FC53FE1A50882C78DB2852CAE474

     :
                                                     Baltimore CyberTrust Root
                                             Baltimore
                                           CyberTrust
                                                  Ireland

     :
                                                     Baltimore CyberTrust Root
                                             Baltimore
                                           CyberTrust
                                                  Ireland

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / DigiCert Global Root G2 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           E5 FA 09 1D B1 64 28 BB A0 A9 11 A7 E6 F1 3A 03
                                            01.08.2013 - 15.01.2038
      MD5 Hash                                          E4A68AC854AC5242460AFD72481B2A44
      SHA1 Hash                                         DF3C24F9BFD666761B268073FE06D1CC8D4F82A4

     :
                                                     DigiCert Global Root G2
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

     :
                                                     DigiCert Global Root G2
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / DigiCert Global Root ]

     :
                                                  V1
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           A5 01
                                            13.08.1998 - 14.08.2018
      MD5 Hash                                          CA3DD368F1035CD032FAB82B59E85ADB
      SHA1 Hash                                         97817950D81C9670CC34D809CF794431367EF474

     :
                                                     GTE CyberTrust Global Root
                                             GTE Corporation
                                           GTE CyberTrust Solutions, Inc.
                                                  United States

     :
                                                     GTE CyberTrust Global Root
                                             GTE Corporation
                                           GTE CyberTrust Solutions, Inc.
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / DigiCert High Assurance EV Root CA ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           77 25 46 AE F2 79 0B 8F 9B 40 0B 6A 26 5C AC 02
                                            10.11.2006 - 10.11.2031
      MD5 Hash                                          D474DE575C39B2D39C8583C5C065498A
      SHA1 Hash                                         5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25

     :
                                                     DigiCert High Assurance EV Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

     :
                                                     DigiCert High Assurance EV Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / DigiCert ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           39 30 F0 1B FC 60 E5 8F FE 46 D8 17 E5 E0 E7 0C
                                            10.11.2006 - 10.11.2031
      MD5 Hash                                          87CE0B7B2A0E4900E158719B37A89372
      SHA1 Hash                                         0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43

     :
                                                     DigiCert Assured ID Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

     :
                                                     DigiCert Assured ID Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / DigiCert ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           4A C7 91 59 C9 6A 75 A1 B1 46 42 90 56 E0 3B 08
                                            10.11.2006 - 10.11.2031
      MD5 Hash                                          79E4A9840D7D3A96D7C04FE2434C892E
      SHA1 Hash                                         A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436

     :
                                                     DigiCert Global Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

     :
                                                     DigiCert Global Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / DigiCert ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           77 25 46 AE F2 79 0B 8F 9B 40 0B 6A 26 5C AC 02
                                            10.11.2006 - 10.11.2031
      MD5 Hash                                          D474DE575C39B2D39C8583C5C065498A
      SHA1 Hash                                         5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25

     :
                                                     DigiCert High Assurance EV Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

     :
                                                     DigiCert High Assurance EV Root CA
                                             DigiCert Inc
                                           www.digicert.com
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / DST Root CA X3 ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           6B 40 F8 2E 86 39 30 89 BA 27 A3 D6 80 B0 AF 44
                                            01.10.2000 - 30.09.2021
      MD5 Hash                                          410352DC0FF7501B16F0028EBA6F45C5
      SHA1 Hash                                         DAC9024F54D8F6DF94935FB1732638CA6AD77C13

     :
                                                     DST Root CA X3
                                             Digital Signature Trust Co.

     :
                                                     DST Root CA X3
                                             Digital Signature Trust Co.

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Entrust.net ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           28 8C 53 4A
                                            07.07.2009 - 07.12.2030
      MD5 Hash                                          4BE2C99196650CF40E5A9392A00AFEB2
      SHA1 Hash                                         8CF427FD790C3AD166068DE81E57EFBB932272D4

     :
                                                     Entrust Root Certification Authority - G2
                                             Entrust, Inc.
                                           See www.entrust.net/legal-terms
                                           (c) 2009 Entrust, Inc. - for authorized use only
                                                  United States

     :
                                                     Entrust Root Certification Authority - G2
                                             Entrust, Inc.
                                           See www.entrust.net/legal-terms
                                           (c) 2009 Entrust, Inc. - for authorized use only
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Entrust ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           54 50 6B 45
                                            27.11.2006 - 27.11.2026
      MD5 Hash                                          D6A5C3ED5DDD3E00C13D87921F1D3FE4
      SHA1 Hash                                         B31EB1B740E36C8402DADC37D44DF5D4674952F9

     :
                                                     Entrust Root Certification Authority
                                             Entrust, Inc.
                                           www.entrust.net/CPS is incorporated by reference
                                           (c) 2006 Entrust, Inc.
                                                  United States

     :
                                                     Entrust Root Certification Authority
                                             Entrust, Inc.
                                           www.entrust.net/CPS is incorporated by reference
                                           (c) 2006 Entrust, Inc.
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / GeoTrust Primary Certification Authority - G3 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           1F 0F 18 C3 A9 27 F6 41 4B 79 B2 19 94 6E AC 15
                                            02.04.2008 - 02.12.2037
      MD5 Hash                                          B5E83436C910445848706D2E83D4B805
      SHA1 Hash                                         039EEDB80BE7A03C6953893B20D2D9323A4C2AFD

     :
                                                     GeoTrust Primary Certification Authority - G3
                                             GeoTrust Inc.
                                           (c) 2008 GeoTrust Inc. - For authorized use only
                                                  United States

     :
                                                     GeoTrust Primary Certification Authority - G3
                                             GeoTrust Inc.
                                           (c) 2008 GeoTrust Inc. - For authorized use only
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / GlobalSign Root CA - R1 ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           94 C3 5A 4B 15 01 00 00 00 00 04
                                            01.09.1998 - 28.01.2028
      MD5 Hash                                          3E455215095192E1B75D379FB187298A
      SHA1 Hash                                         B1BC968BD4F49D622AA89A81F2150152A41D829C

     :
                                                     GlobalSign Root CA
                                             GlobalSign nv-sa
                                           Root CA
                                                  Belgium

     :
                                                     GlobalSign Root CA
                                             GlobalSign nv-sa
                                           Root CA
                                                  Belgium

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / GlobalSign Root CA - R3 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           A2 08 53 58 21 01 00 00 00 00 04
                                            18.03.2009 - 18.03.2029
      MD5 Hash                                          C5DFB849CA051355EE2DBA1AC33EB028
      SHA1 Hash                                         D69B561148F01C77C54578C10926DF5B856976AD

     :
                                                     GlobalSign
                                             GlobalSign
                                           GlobalSign Root CA - R3

     :
                                                     GlobalSign
                                             GlobalSign
                                           GlobalSign Root CA - R3

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Go Daddy Class 2 Certification Authority ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           00
                                            29.06.2004 - 29.06.2034
      MD5 Hash                                          91DE0625ABDAFD32170CBB25172A8467
      SHA1 Hash                                         2796BAE63F1801E277261BA0D77770028F20EEE4

     :
                                             The Go Daddy Group, Inc.
                                           Go Daddy Class 2 Certification Authority
                                                  United States

     :
                                             The Go Daddy Group, Inc.
                                           Go Daddy Class 2 Certification Authority
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Go Daddy Root Certificate Authority  G2 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           00
                                            01.09.2009 - 01.01.2038
      MD5 Hash                                          803ABC22C1E6FB8D9B3B274A321B9A01
      SHA1 Hash                                         47BEABC922EAE80E78783462A79F45C254FDE68B

     :
                                                     Go Daddy Root Certificate Authority - G2
                                             GoDaddy.com, Inc.
                                                  United States
                                         Scottsdale
      /                                     Arizona

     :
                                                     Go Daddy Root Certificate Authority - G2
                                             GoDaddy.com, Inc.
                                                  United States
                                         Scottsdale
      /                                     Arizona

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Google Trust Services - GlobalSign Root CA-R2 ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           0D E6 26 86 0F 01 00 00 00 00 04
                                            15.12.2006 - 15.12.2021
      MD5 Hash                                          9414777E3E5EFD8F30BD41B0CFE7D030
      SHA1 Hash                                         75E0ABB6138512271C04F85FDDDE38E4B7242EFE

     :
                                                     GlobalSign
                                             GlobalSign
                                           GlobalSign Root CA - R2

     :
                                                     GlobalSign
                                             GlobalSign
                                           GlobalSign Root CA - R2

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Microsoft Authenticode(tm) Root ]

     :
                                                  V3
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           01
                                            01.01.1995 - 01.01.2000
      MD5 Hash                                          DC6D6FAF897CDD17332FB5BA9035E9CE
      SHA1 Hash                                         7F88CD7223F3C813818C994614A89C99FA3B5247

     :
                                                     Microsoft Authenticode(tm) Root Authority
                                             MSFT
                                                  United States

     :
                                                     Microsoft Authenticode(tm) Root Authority
                                             MSFT
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Microsoft Root Authority ]

     :
                                                  V3
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           40 DF EC 63 F6 3E D1 11 88 3C 3C 8B 00 C1 00
                                            10.01.1997 - 31.12.2020
      MD5 Hash                                          2A954ECA79B2874573D92D90BAF99FB6
      SHA1 Hash                                         A43489159A520F0D93D032CCAF37E7FE20A8B419

     :
                                                     Microsoft Root Authority
                                           Copyright (c) 1997 Microsoft Corp.
                                           Microsoft Corporation

     :
                                                     Microsoft Root Authority
                                           Copyright (c) 1997 Microsoft Corp.
                                           Microsoft Corporation

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Microsoft Root Certificate Authority 2010 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           AA 39 43 6B 58 9B 9A 44 AC 44 BA BF 25 3A CC 28
                                            24.06.2010 - 24.06.2035
      MD5 Hash                                          A266BB7DCC38A562631361BBF61DD11B
      SHA1 Hash                                         3B1EFD3A66EA28B16697394703A72CA340A05BD5

     :
                                                     Microsoft Root Certificate Authority 2010
                                             Microsoft Corporation
                                                  United States
                                         Redmond
      /                                     Washington

     :
                                                     Microsoft Root Certificate Authority 2010
                                             Microsoft Corporation
                                                  United States
                                         Redmond
      /                                     Washington

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Microsoft Root Certificate Authority 2011 ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           44 E1 42 6C D6 69 B5 43 96 B2 9F FC B5 C8 8B 3F
                                            23.03.2011 - 23.03.2036
      MD5 Hash                                          CE0490D5E56C34A5AE0BE98BE581185D
      SHA1 Hash                                         8F43288AD272F3103B6FB1428485EA3014C0BCFE

     :
                                                     Microsoft Root Certificate Authority 2011
                                             Microsoft Corporation
                                                  United States
                                         Redmond
      /                                     Washington

     :
                                                     Microsoft Root Certificate Authority 2011
                                             Microsoft Corporation
                                                  United States
                                         Redmond
      /                                     Washington

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Microsoft Root Certificate Authority ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           65 2E 13 07 F4 58 73 4C AD A5 A0 4A A1 16 AD 79
                                            10.05.2001 - 10.05.2021
      MD5 Hash                                          E1C07EA0AABBD4B77B84C228117808A7
      SHA1 Hash                                         CDD4EEAE6000AC7F40C3802C171E30148030C072

     :
                                                     Microsoft Root Certificate Authority

     :
                                                     Microsoft Root Certificate Authority

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Microsoft Timestamp Root ]

     :
                                                  V1
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           01
                                            13.05.1997 - 31.12.1999
      MD5 Hash                                          556EBEF54C1D7C0360C43418BC9649C1
      SHA1 Hash                                         245C97DF7514E7CF2DF8BE72AE957B9E04741E85

     :
                                             Microsoft Trust Network
                                           Microsoft Corporation
                                           Microsoft Time Stamping Service Root

     :
                                             Microsoft Trust Network
                                           Microsoft Corporation
                                           Microsoft Time Stamping Service Root

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / SECOM Trust Systems CO LTD ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           00
                                            30.09.2003 - 30.09.2023
      MD5 Hash                                          F1BC636A54E0B527F5CDE71AE34D6E4A
      SHA1 Hash                                         36B12B49F9819ED74C9EBC380FC6568F5DACB2F7

     :
                                             SECOM Trust.net
                                           Security Communication RootCA1
                                                  Japan

     :
                                             SECOM Trust.net
                                           Security Communication RootCA1
                                                  Japan

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Sectigo (AAA) ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           01
                                            01.01.2004 - 01.01.2029
      MD5 Hash                                          497904B0EB8719AC47B0BC11519B74D0
      SHA1 Hash                                         D1EB23A46D17D68FD92564C2F1F1601764D8E349

     :
                                                     AAA Certificate Services
                                             Comodo CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

     :
                                                     AAA Certificate Services
                                             Comodo CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Sectigo (AddTrust) ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           01
                                            30.05.2000 - 30.05.2020
      MD5 Hash                                          1D3554048578B03F42424DBF20730A3F
      SHA1 Hash                                         02FAF3E291435468607857694DF5E45B68851868

     :
                                                     AddTrust External CA Root
                                             AddTrust AB
                                           AddTrust External TTP Network
                                                  Sweden

     :
                                                     AddTrust External CA Root
                                             AddTrust AB
                                           AddTrust External TTP Network
                                                  Sweden

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Sectigo (formerly Comodo CA) ]

     :
                                                  V3
                                         SHA384 RSA  (1.2.840.113549.1.1.12)
                                           9D 86 03 5B D8 4E F7 1F E0 6F 63 DB CA F9 AA 4C
                                            19.01.2010 - 19.01.2038
      MD5 Hash                                          1B31B0714036CC143691ADC43EFDEC18
      SHA1 Hash                                         AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4

     :
                                                     COMODO RSA Certification Authority
                                             COMODO CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

     :
                                                     COMODO RSA Certification Authority
                                             COMODO CA Limited
                                                  United Kingdom
                                         Salford
      /                                     Greater Manchester

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Sectigo (UTN Object) ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           1B 5F B3 E0 2D 36 D3 11 B4 24 00 50 8B 0C BE 44
                                            09.07.1999 - 09.07.2019
      MD5 Hash                                          A7F2E41606411150306B9CE3B49CB0C9
      SHA1 Hash                                         E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46

     :
                                                     UTN-USERFirst-Object
                                             The USERTRUST Network
                                           http://www.usertrust.com
                                                  United States
                                         Salt Lake City
      /                                     UT

     :
                                                     UTN-USERFirst-Object
                                             The USERTRUST Network
                                           http://www.usertrust.com
                                                  United States
                                         Salt Lake City
      /                                     UT

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Sectigo ECC ]

     :
                                                  V3
                                         1.2.840.10045.4.3.3
                                           26 CC 80 89 CD DE 56 71 D2 C5 94 5A C5 99 8B 5C
                                            01.02.2010 - 19.01.2038
      MD5 Hash                                          FA68BCD9B57FADFDC91D068328CC24C1
      SHA1 Hash                                         D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0

     :
                                                     USERTrust ECC Certification Authority
                                             The USERTRUST Network
                                                  United States
                                         Jersey City
      /                                     New Jersey

     :
                                                     USERTrust ECC Certification Authority
                                             The USERTRUST Network
                                                  United States
                                         Jersey City
      /                                     New Jersey

      :
                                 1.2.840.10045.2.1

  [ Root Certificates / Sectigo ]

     :
                                                  V3
                                         SHA384 RSA  (1.2.840.113549.1.1.12)
                                           2D 03 35 0E 64 BC 1B A8 51 CA A3 FC 30 6D FD 01
                                            01.02.2010 - 19.01.2038
      MD5 Hash                                          1BFE69D191B71933A372A80FE155E5B5
      SHA1 Hash                                         2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E

     :
                                                     USERTrust RSA Certification Authority
                                             The USERTRUST Network
                                                  United States
                                         Jersey City
      /                                     New Jersey

     :
                                                     USERTrust RSA Certification Authority
                                             The USERTRUST Network
                                                  United States
                                         Jersey City
      /                                     New Jersey

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Simplix Root Authority ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           82 AF 4A B2 04 5F 99 D7 00
                                            10.01.1997 - 31.12.2020
      MD5 Hash                                          B25C2DE8AEB765180C2B3FF68CACE247
      SHA1 Hash                                         87C47CBB95638C2264392D88EEBCAE6AD9F84764

     :
                                             Simplix Root Authority

     :
                                             Simplix Root Authority

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Starfield Class 2 Certification Authority ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           00
                                            29.06.2004 - 29.06.2034
      MD5 Hash                                          324A4BBBC863699BBE749AC6DD1D4624
      SHA1 Hash                                         AD7E1C28B064EF8F6003402014C3D0E3370EB58A

     :
                                             Starfield Technologies, Inc.
                                           Starfield Class 2 Certification Authority
                                                  United States

     :
                                             Starfield Technologies, Inc.
                                           Starfield Class 2 Certification Authority
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / StartCom Certification Authority ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           01
                                            17.09.2006 - 17.09.2036
      MD5 Hash                                          224D8F8AFCF735C2BB5734907B8B2216
      SHA1 Hash                                         3E2BF7F2031B96F38CE6C4D8A85D3E2D58476A0F

     :
                                                     StartCom Certification Authority
                                             StartCom Ltd.
                                           Secure Digital Certificate Signing
                                                  Israel

     :
                                                     StartCom Certification Authority
                                             StartCom Ltd.
                                           Secure Digital Certificate Signing
                                                  Israel

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Thawte Timestamping CA ]

     :
                                                  V3
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           00
                                            01.01.1997 - 01.01.2021
      MD5 Hash                                          7F667A71D3EB6978209A51149D83DA20
      SHA1 Hash                                         BE36A4562FB2EE05DBB3D32323ADF445084ED656

     :
                                                     Thawte Timestamping CA
                                             Thawte
                                           Thawte Certification
                                                  South Africa
                                         Durbanville
      /                                     Western Cape

     :
                                                     Thawte Timestamping CA
                                             Thawte
                                           Thawte Certification
                                                  South Africa
                                         Durbanville
      /                                     Western Cape

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / thawte ]

     :
                                                  V3
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           01
                                            01.08.1996 - 01.01.2021
      MD5 Hash                                          069F6979166690021B8C8CA2C3076F3A
      SHA1 Hash                                         627F8D7827656399D27D7F9044C9FEB3F33EFA9A

     :
                                                     Thawte Premium Server CA
                                             Thawte Consulting cc
                                           Certification Services Division
                                                  South Africa
                                         Cape Town
      /                                     Western Cape
      E-mail                                            premium-server@thawte.com

     :
                                                     Thawte Premium Server CA
                                             Thawte Consulting cc
                                           Certification Services Division
                                                  South Africa
                                         Cape Town
      /                                     Western Cape
      E-mail                                            premium-server@thawte.com

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / thawte ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           6D 2B DB 37 CE 2F F4 49 EC ED D5 20 57 D5 4E 34
                                            17.11.2006 - 17.07.2036
      MD5 Hash                                          8CCADC0B22CEF5BE72AC411A11A8D812
      SHA1 Hash                                         91C6D6EE3E8AC86384E548C299295C756C817B81

     :
                                                     thawte Primary Root CA
                                             thawte, Inc.
                                           Certification Services Division
                                           (c) 2006 thawte, Inc. - For authorized use only
                                                  United States

     :
                                                     thawte Primary Root CA
                                             thawte, Inc.
                                           Certification Services Division
                                           (c) 2006 thawte, Inc. - For authorized use only
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / Trustwave ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           D0 59 18 27 EB F0 7F 42 AD A5 16 08 5C 8E F0 0C
                                            07.11.2006 - 31.12.2029
      MD5 Hash                                          DC32C3A76D2557C768099DEA2DA9A2D1
      SHA1 Hash                                         8782C6C304353BCFD29692D2593E7D44D934FF11

     :
                                                     SecureTrust CA
                                             SecureTrust Corporation
                                                  United States

     :
                                                     SecureTrust CA
                                             SecureTrust Corporation
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / VeriSign Class 3 Public Primary CA ]

     :
                                                  V1
                                         MD2 RSA  (1.2.840.113549.1.1.2)
                                           BF BA CC 03 7B CA 38 B6 34 29 D9 10 1D E4 BA 70
                                            29.01.1996 - 02.08.2028
      MD5 Hash                                          10FC635DF6263E0DF325BE5F79CD6767
      SHA1 Hash                                         742C3192E607E424EB4549542BE1BBC53E6174E2

     :
                                             VeriSign, Inc.
                                           Class 3 Public Primary Certification Authority
                                                  United States

     :
                                             VeriSign, Inc.
                                           Class 3 Public Primary Certification Authority
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / VeriSign Time Stamping CA ]

     :
                                                  V1
                                         MD5 RSA  (1.2.840.113549.1.1.4)
                                           A3 DC 5D 15 5F 73 5D A5 1C 59 82 8C 38 D2 19 4A
                                            12.05.1997 - 08.01.2004
      MD5 Hash                                          EBB04F1D3A2E372F1DDA6E27D6B680FA
      SHA1 Hash                                         18F7C1FCC3090203FD5BAA2F861A754976C8DD25

     :
                                             VeriSign Trust Network
                                           VeriSign, Inc.
                                           VeriSign Time Stamping Service Root
                                           NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.

     :
                                             VeriSign Trust Network
                                           VeriSign, Inc.
                                           VeriSign Time Stamping Service Root
                                           NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / VeriSign Universal Root Certification Authority ]

     :
                                                  V3
                                         SHA256 RSA  (1.2.840.113549.1.1.11)
                                           1D C5 1A 12 E4 BB 0E 03 21 13 B3 21 64 C4 1A 40
                                            02.04.2008 - 02.12.2037
      MD5 Hash                                          8EADB501AA4D81E48C1DD1E114009519
      SHA1 Hash                                         3679CA35668772304D30A5FB873B0FA77BB70D54

     :
                                                     VeriSign Universal Root Certification Authority
                                             VeriSign, Inc.
                                           VeriSign Trust Network
                                           (c) 2008 VeriSign, Inc. - For authorized use only
                                                  United States

     :
                                                     VeriSign Universal Root Certification Authority
                                             VeriSign, Inc.
                                           VeriSign Trust Network
                                           (c) 2008 VeriSign, Inc. - For authorized use only
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)

  [ Root Certificates / VeriSign ]

     :
                                                  V3
                                         SHA1 RSA  (1.2.840.113549.1.1.5)
                                           4A 3B 6B CC CD 58 21 4A BB E8 7D 26 9E D1 DA 18
                                            08.11.2006 - 17.07.2036
      MD5 Hash                                          CB17E431673EE209FE455793F30AFA1C
      SHA1 Hash                                         4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5

     :
                                                     VeriSign Class 3 Public Primary Certification Authority - G5
                                             VeriSign, Inc.
                                           VeriSign Trust Network
                                           (c) 2006 VeriSign, Inc. - For authorized use only
                                                  United States

     :
                                                     VeriSign Class 3 Public Primary Certification Authority - G5
                                             VeriSign, Inc.
                                           VeriSign Trust Network
                                           (c) 2006 VeriSign, Inc. - For authorized use only
                                                  United States

      :
                                 RSA  (1.2.840.113549.1.1.1)


--------[   ]------------------------------------------------------------------------------------------------

     :
                         06.06.2020 9:00:20
                           06.06.2020 9:00:35
                                   15  (0 ., 0 , 0 , 15 )
                                            06.06.2020 9:07:22
                                             408  (0 ., 0 , 6 , 47 )

      :
                                     20.01.2020 13:08:49
                            20.01.2020 13:11:06
                                        7263257  (84 ., 1 , 34 , 16 )
                                       4645457  (53 ., 18 , 24 , 17 )
                                  725425  (8 ., 9 , 30 , 25 )
                                 63996  (0 ., 17 , 46 , 36 )
                                       293
                                60.99%

      (" "):
                                        27.03.2020 16:29:02
                                     06.06.2020 8:28:37
                                              37

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    ADMIN$                                    Admin                           C:\Windows
    C$                                                           C:\
    D$                                                           D:\
    IPC$                            IPC            IPC                             


--------[  ]------------------------------------------------------------------------------------------------

       :
                                          
                                             Home-
                              
                      
      ./.                      0 / 42 .
                                  0 
                                     
                                       
                                30 
                                30 


--------[    ]----------------------------------------------------------------------------------------------

    Home                                          HOME-                   Home-
    Home                                          HOME-                   Home-


--------[  ]------------------------------------------------------------------------------------------------

  [ Home ]

     :
                                         Home
                                               Home
                                               
                                     196
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                 /
                                               
                                     22
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[   ]--------------------------------------------------------------------------------------------

  [ IIS_IUSRS ]

      :
                                              ,    IIS.

     :
      IUSR                                              

  [  ]

      :
                                               ,         

     :
      Home                                              
                                           

  [  ]

      :
                                                   ,   ,     "",     .

     :
                                                   

  [   ]

      :
                                                 .

  [   ]

      :
                                                         .

  [    ]

      :
                                                         

  [   ]

      :
                                                        

  [  DCOM ]

      :
                                                 ,     DCOM   .

  [    ]

      :
                                                     ,         ,        .

  [    ]

      :
                                                  ,       

  [     ]

      :
                                                     

  [  ]

      :
                                                         

     :
                                           
                                       

  [  ]

      :
                                                 

  [    ]

      :
                                                      


--------[   ]-------------------------------------------------------------------------------------------

  [ None ]

      :
                                             Ordinary users

     :
      Home                                              
                                           
                                                   


--------[  Windows ]-----------------------------------------------------------------------------------------------

  [ AMD Radeon R7 240 Series ]

     :
                                      AMD Radeon R7 240 Series
                                          AMD Radeon R7 240 Series
       BIOS                                       113-H240A-2TSX-100-06
                                      AMD Radeon Graphics Processor (0x6617)
       DAC                                           Internal DAC(400MHz)
                                            21.04.2020
                                          26.20.15029.27016
                                       Advanced Micro Devices, Inc.
                                           2 

     :
      aticfx64                                          8.17.10.1680
      aticfx64                                          8.17.10.1680
      aticfx64                                          8.17.10.1680
      amdxc64                                           8.18.10.0349
      aticfx32                                          8.17.10.1680
      aticfx32                                          8.17.10.1680
      aticfx32                                          8.17.10.1680
      amdxc32                                           8.18.10.0349
      atiumd64                                          9.14.10.01432
      atidxx64                                          8.17.10.0927
      atidxx64                                          8.17.10.0927
      atiumdag                                          9.14.10.01432
      atidxx32                                          8.17.10.0927
      atidxx32                                          8.17.10.0927
      atiumdva                                          8.14.10.0683
      atiumd6a                                          8.14.10.0683
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates

  [ AMD Radeon R7 240 Series ]

     :
                                      AMD Radeon R7 240 Series
                                          AMD Radeon R7 240 Series
       BIOS                                       113-H240A-2TSX-100-06
                                      AMD Radeon Graphics Processor (0x6617)
       DAC                                           Internal DAC(400MHz)
                                            21.04.2020
                                          26.20.15029.27016
                                       Advanced Micro Devices, Inc.
                                           2 

     :
      aticfx64                                          8.17.10.1680
      aticfx64                                          8.17.10.1680
      aticfx64                                          8.17.10.1680
      amdxc64                                           8.18.10.0349
      aticfx32                                          8.17.10.1680
      aticfx32                                          8.17.10.1680
      aticfx32                                          8.17.10.1680
      amdxc32                                           8.18.10.0349
      atiumd64                                          9.14.10.01432
      atidxx64                                          8.17.10.0927
      atidxx64                                          8.17.10.0927
      atiumdag                                          9.14.10.01432
      atidxx32                                          8.17.10.0927
      atidxx32                                          8.17.10.0927
      atiumdva                                          8.14.10.0683
      atiumd6a                                          8.14.10.0683
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates

  [ AMD Radeon R7 240 Series ]

     :
                                      AMD Radeon R7 240 Series
                                          AMD Radeon R7 240 Series
       BIOS                                       113-H240A-2TSX-100-06
                                      AMD Radeon Graphics Processor (0x6617)
       DAC                                           Internal DAC(400MHz)
                                            21.04.2020
                                          26.20.15029.27016
                                       Advanced Micro Devices, Inc.
                                           2 

     :
      aticfx64                                          8.17.10.1680
      aticfx64                                          8.17.10.1680
      aticfx64                                          8.17.10.1680
      amdxc64                                           8.18.10.0349
      aticfx32                                          8.17.10.1680
      aticfx32                                          8.17.10.1680
      aticfx32                                          8.17.10.1680
      amdxc32                                           8.18.10.0349
      atiumd64                                          9.14.10.01432
      atidxx64                                          8.17.10.0927
      atidxx64                                          8.17.10.0927
      atiumdag                                          9.14.10.01432
      atidxx32                                          8.17.10.0927
      atidxx32                                          8.17.10.0927
      atiumdva                                          8.14.10.0683
      atiumd6a                                          8.14.10.0683
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates

  [ AMD Radeon R7 240 Series ]

     :
                                      AMD Radeon R7 240 Series
                                          AMD Radeon R7 240 Series
       BIOS                                       113-H240A-2TSX-100-06
                                      AMD Radeon Graphics Processor (0x6617)
       DAC                                           Internal DAC(400MHz)
                                            21.04.2020
                                          26.20.15029.27016
                                       Advanced Micro Devices, Inc.
                                           2 

     :
      aticfx64                                          8.17.10.1680
      aticfx64                                          8.17.10.1680
      aticfx64                                          8.17.10.1680
      amdxc64                                           8.18.10.0349
      aticfx32                                          8.17.10.1680
      aticfx32                                          8.17.10.1680
      aticfx32                                          8.17.10.1680
      amdxc32                                           8.18.10.0349
      atiumd64                                          9.14.10.01432
      atidxx64                                          8.17.10.0927
      atidxx64                                          8.17.10.0927
      atiumdag                                          9.14.10.01432
      atidxx32                                          8.17.10.0927
      atidxx32                                          8.17.10.0927
      atiumdva                                          8.14.10.0683
      atiumd6a                                          8.14.10.0683
      atitmm64                                          6.14.11.25

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates


--------[  PCI / AGP ]---------------------------------------------------------------------------------------------

    AMD Radeon R5 420                                                                 
    AMD Radeon R5 420                                                                 3D-


--------[   ]---------------------------------------------------------------------------------------

  [ PCI Express 2.0 x8: AMD Radeon R7 240 (Oland) ]

      :
                                            AMD Radeon R7 240 (Oland)
       BIOS                                       015.049.000.013.000000
       BIOS                                         14.07.2016
                                       Oland
                                          113-H240A-2TSX-100-06
      PCI-                                    1002-6617 / 1787-2000  (Rev C7)
                                       900 
                                  28 nm
                                         90 mm2
      ASIC Quality                                      70.7%
                                                 PCI Express 2.0 x8 @ 2.0 x8
                                           2 
                                               300   (: 700 )
       RAMDAC                                    400 
                                     8
                                 20
                                     320  (v5.1)
        DirectX                      DirectX v11.2
      PowerControl                                      0%
       WDDM                                       WDDM 1.1

      :
                                                 DDR3
                                              128 
                                         800  (DDR)  (: 800 )
                                      1600 
                                   25.0 /

    :
                                             AMD GCN
        (CU)                       5
      SIMD                         4
       SIMD                                       16
        SIMD                            1
       L1                                  32  per CU-Quad
       L1                             16  per CU
       L1                             16  per CU-Quad
       L2                                            256 
      Local Data Share                                  64 
      Global Data Share                                 64 

      :
                            2400 / @ 300 
                            6000 / @ 300 
      FLOPS                          192.0 GFLOPS @ 300 
      FLOPS                            12.0 GFLOPS @ 300 
      24-  IOPS                   192.0 GIOPS @ 300 
      32-  IOPS                   38.4 GIOPS @ 300 

    :
                                    23%
                                        147 
                                      60 

    ATI PowerPlay (BIOS):
      State #1                                           : 700 , : 800   (Boot)
      State #2                                           : 700 , : 800 
      State #3                                           : 650 , : 800   (UVD)

      :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates

    ATI GPU Registers:
      ati-$0174                                         00002D31
      ati-$0600                                         80400000
      ati-$0604                                         00000001
      ati-$0608                                         100B1C71
      ati-$061C                                         01F42000
      ati-$0624                                         00000000
      ati-$0628                                         0000FF14
      ati-$062C                                         00000600
      ati-$0660                                         00000001
      ati-$0664                                         00510009
      ati-$0668                                         04077F02
      ati-$0704                                         00005800
      ati-$0710                                         00000101
      ati-$0714                                         00003C1F
      ati-$0758                                         401E1F7D
      ati-$0760                                         003F003F
      ati-$0774                                         00003651
      ati-$0780                                         00800403
      ati-$078C                                         00000000
      ati-$0794                                         00010541
      ati-$0798                                         08211111
      ati-$07FC                                         00006978
      ati-$0874                                         11110000
      ati-$1600                                         11030302
      ati-$2004                                         00002210
      ati-$2408                                         000F007F
      ati-$25B8                                         00000000
      ati-$2760                                         000012A1
      ati-$29F8                                         FFFFFFFF
      ati-$29FC                                         FFFFFFFF
      ati-$2A00                                         B0000F2B
      ati-$2A04                                         40061C70
      ati-$2BA0                                         010003CA
      ati-$2BA4                                         002581F4
      ati-$2BB0                                         05000910
      ati-$2BB4                                         C2180800
      ati-$2BB8                                         003B2121
      ati-$2BBC                                         00002004
      ati-$2BC0                                         00000000
      ati-$2BC4                                         00000012
      ati-$2BCC                                         0000002A
      ati-$2BD0                                         000001C2
      ati-$5428                                         00000800
      ati-$802C                                         00000000
      ati-$89BC                                         FFC00000  [SE0 SH0]
      ati-$89C0                                         00010000  [SE0 SH0]
      ati-$89BC                                         00000000  [SE0 SH1]
      ati-$89C0                                         00000000  [SE0 SH1]
      ati-$89BC                                         00000000  [SE1 SH0]
      ati-$89C0                                         00000000  [SE1 SH0]
      ati-$89BC                                         00000000  [SE1 SH1]
      ati-$89C0                                         00000000  [SE1 SH1]
      ati-$98F0                                         00000000
      ati-$98F4                                         00000000
      ati-$98F8                                         00000000
      ati-$98FC                                         00000000
      ati-$9B7C                                         00000000


--------[  ]-----------------------------------------------------------------------------------------------------

  [ LG E1941 (Analog) ]

     :
                                             LG E1941 (Analog)
      ID                                        GSM4BF0
                                                  E1941
                                             18.5" LCD (WXGA)
                                              3 / 2011
                                           103TPAE3B104
      .                         410 mm x 230 mm (18.5")
                                       16:9
                                            30 - 61 
                                           56 - 75 
                           90 
                                  1366 x 768
                                       85 ppi
                                                   2.20
        DPMS                        Standby, Suspend, Active-Off

     :
      640 x 480                                         60 
      640 x 480                                         75 
      720 x 400                                         70 
      800 x 600                                         56 
      800 x 600                                         60 
      800 x 600                                         75 
      832 x 624                                         75 
      1024 x 768                                        60 
      1024 x 768                                        75 
      1366 x 768                                         : 85.50 

     :
                                                   LG Electronics
                                     http://www.lg.com/us/monitors
                                       http://www.lg.com/us/support
                                     http://www.aida64.com/goto/?p=drvupdates


--------[   ]------------------------------------------------------------------------------------------------

      :
                                     
                                              1366 x 768
                                            32 
                                       1
                                        96 dpi
                           ,  
        /                         36 / 36
                                     51
                                      60 
                                    C:\Users\Home\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

      :
       -                             
      Dark Mode                                          
                                              
                                      
                              
      ClearType                                         
                   
                                
                                  
                                      
                                  
                                 
                                            
                                   
       /           
                                           
                              
                               
                                         
                                            
                                     
                            
                              
      Windows Aero                                      
       Windows Plus!                               


--------[  ]-----------------------------------------------------------------------------------------------

    \\.\DISPLAY1           (0,0)          (1366,768)


--------[  ]-------------------------------------------------------------------------------------------------

    640 x 480           8   60 Hz
    640 x 480           8   75 Hz
    640 x 480          16   60 Hz
    640 x 480          16   75 Hz
    640 x 480          32   60 Hz
    640 x 480          32   75 Hz
    720 x 400           8   60 Hz
    720 x 400           8   60 Hz
    720 x 400           8   60 Hz
    720 x 400           8   70 Hz
    720 x 400          16   60 Hz
    720 x 400          16   60 Hz
    720 x 400          16   60 Hz
    720 x 400          16   70 Hz
    720 x 400          32   60 Hz
    720 x 400          32   60 Hz
    720 x 400          32   60 Hz
    720 x 400          32   70 Hz
    800 x 600           8   56 Hz
    800 x 600           8   60 Hz
    800 x 600           8   75 Hz
    800 x 600          16   56 Hz
    800 x 600          16   60 Hz
    800 x 600          16   75 Hz
    800 x 600          32   56 Hz
    800 x 600          32   60 Hz
    800 x 600          32   75 Hz
    832 x 624           8   60 Hz
    832 x 624           8   60 Hz
    832 x 624           8   60 Hz
    832 x 624           8   75 Hz
    832 x 624          16   60 Hz
    832 x 624          16   60 Hz
    832 x 624          16   60 Hz
    832 x 624          16   75 Hz
    832 x 624          32   60 Hz
    832 x 624          32   60 Hz
    832 x 624          32   60 Hz
    832 x 624          32   75 Hz
    1024 x 768          8   60 Hz
    1024 x 768          8   75 Hz
    1024 x 768         16   60 Hz
    1024 x 768         16   75 Hz
    1024 x 768         32   60 Hz
    1024 x 768         32   75 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         32   60 Hz
    1360 x 768         32   60 Hz
    1360 x 768         32   60 Hz
    1366 x 768          8   60 Hz
    1366 x 768         16   60 Hz
    1366 x 768         32   60 Hz


--------[ OpenGL ]------------------------------------------------------------------------------------------------------

     OpenGL:
                                           ATI Technologies Inc.
      Renderer                                          AMD Radeon R7 240 Series
                                                  4.6.13587 Compatibility Profile Context 20.4.2 26.20.15029.27016
                                    4.60
      OpenGL DLL                                        6.1.7600.16385(win7_rtm.090713-1255)
      Multitexture Texture Units                        8
      Occlusion Query Counter Bits                      32
      Sub-Pixel Precision                               8 
      Max Viewport Size                                 16384 x 16384
      Max Cube Map Texture Size                         16384 x 16384
      Max Rectangle Texture Size                        16384 x 16384
      Max 3D Texture Size                               2048 x 2048 x 2048
      Max Anisotropy                                    16
      Max Clipping Planes                               8
      Max Display-List Nesting Level                    64
      Max Draw Buffers                                  8
      Max Evaluator Order                               40
      Max Light Sources                                 8
      Max Pixel Map Table Size                          256
      Min / Max Program Texel Offset                    -8 / 7
      Max Texture Array Layers                          2048
      Max Texture LOD Bias                              16

     OpenGL:
      OpenGL 1.1                                          (100%)
      OpenGL 1.2                                          (100%)
      OpenGL 1.3                                          (100%)
      OpenGL 1.4                                          (100%)
      OpenGL 1.5                                          (100%)
      OpenGL 2.0                                          (100%)
      OpenGL 2.1                                          (100%)
      OpenGL 3.0                                          (100%)
      OpenGL 3.1                                          (100%)
      OpenGL 3.2                                          (100%)
      OpenGL 3.3                                          (100%)
      OpenGL 4.0                                          (100%)
      OpenGL 4.1                                          (100%)
      OpenGL 4.2                                          (100%)
      OpenGL 4.3                                          (100%)
      OpenGL 4.4                                          (100%)
      OpenGL 4.5                                          (100%)
      OpenGL 4.6                                          (100%)

    Max Stack Depth:
      Attribute Stack                                   16
      Client Attribute Stack                            16
      Modelview Matrix Stack                            32
      Name Stack                                        64
      Projection Matrix Stack                           10
      Texture Matrix Stack                              10

    Draw Range Elements:
      Max Index Count                                   536870911
      Max Vertex Count                                  536870911

    Transform Feedback:
      Max Interleaved Components                        128
      Max Separate Attributes                           4
      Max Separate Components                           4

    Framebuffer Object:
      Max Color Attachments                             8
      Max Render Buffer Size                            16384 x 16384

    Imaging:
      Max Color Matrix Stack Depth                      10
      Max Convolution Width / Height                    11 / 11

    Vertex Shader:
      Max Uniform Vertex Components                     16384
      Max Varying Floats                                128
      Max Vertex Texture Image Units                    32
      Max Combined Texture Image Units                  160

    Geometry Shader:
      Max Geometry Texture Units                        32
      Max Varying Components                            128
      Max Geometry Varying Components                   128
      Max Vertex Varying Components                     128
      Max Geometry Uniform Components                   16384
      Max Geometry Output Vertices                      1023
      Max Geometry Total Output Components              4095

    Fragment Shader:
      Max Uniform Fragment Components                   16384
      Max Fragment Registers                            6
      Max Fragment Constants                            8
      Max Passes                                        2
      Max Instructions Per Pass                         8
      Max Total Instructions                            16
      Max Input Interpolator Components                 3
      Max Loopback Components                           3

    Vertex Program:
      Max Local Parameters                              256
      Max Environment Parameters                        256
      Max Program Matrices                              32
      Max Program Matrix Stack Depth                    32
      Max Vertex Attributes                             29
      Max Instructions                                  2147483647
      Max Native Instructions                           2147483647
      Max Temporaries                                   320
      Max Native Temporaries                            256
      Max Parameters                                    256
      Max Native Parameters                             256
      Max Attributes                                    29
      Max Native Attributes                             32
      Max Address Registers                             1
      Max Native Address Registers                      1

    Fragment Program:
      Max Local Parameters                              256
      Max Environment Parameters                        256
      Max Texture Coordinates                           16
      Max Texture Image Units                           32
      Max Instructions                                  2147483647
      Max Native Instructions                           2147483647
      Max Temporaries                                   320
      Max Native Temporaries                            256
      Max Parameters                                    256
      Max Native Parameters                             256
      Max Attributes                                    29
      Max Native Attributes                             16
      Max Address Registers                             0
      Max Native Address Registers                      0
      Max ALU Instructions                              2147483647
      Max Native ALU Instructions                       2147483647
      Max Texture Instructions                          2147483647
      Max Native Texture Instructions                   2147483647
      Max Texture Indirections                          2147483647
      Max Native Texture Indirections                   2147483647

     OpenGL:
       /                   1074 / 322
      GL_3DFX_multisample                                
      GL_3DFX_tbuffer                                    
      GL_3DFX_texture_compression_FXT1                   
      GL_3DL_direct_texture_access2                      
      GL_3Dlabs_multisample_transparency_id              
      GL_3Dlabs_multisample_transparency_range           
      GL_AMD_blend_minmax_factor                        
      GL_AMD_compressed_3DC_texture                      
      GL_AMD_compressed_ATC_texture                      
      GL_AMD_conservative_depth                         
      GL_AMD_debug_output                               
      GL_AMD_depth_clamp_separate                       
      GL_AMD_draw_buffers_blend                         
      GL_AMD_framebuffer_sample_positions               
      GL_AMD_gcn_shader                                 
      GL_AMD_gpu_shader_half_float                       
      GL_AMD_gpu_shader_half_float_fetch                 
      GL_AMD_gpu_shader_half_float2                      
      GL_AMD_gpu_shader_int16                            
      GL_AMD_gpu_shader_int64                           
      GL_AMD_interleaved_elements                       
      GL_AMD_multi_draw_indirect                        
      GL_AMD_name_gen_delete                            
      GL_AMD_occlusion_query_event                       
      GL_AMD_performance_monitor                        
      GL_AMD_pinned_memory                              
      GL_AMD_program_binary_Z400                         
      GL_AMD_query_buffer_object                        
      GL_AMD_sample_positions                           
      GL_AMD_seamless_cubemap_per_texture               
      GL_AMD_shader_atomic_counter_ops                  
      GL_AMD_shader_stencil_export                      
      GL_AMD_shader_stencil_value_export                
      GL_AMD_shader_trace                               
      GL_AMD_shader_trinary_minmax                      
      GL_AMD_sparse_texture                             
      GL_AMD_sparse_texture_pool                         
      GL_AMD_stencil_operation_extended                 
      GL_AMD_texture_compression_dxt6                    
      GL_AMD_texture_compression_dxt7                    
      GL_AMD_texture_cube_map_array                     
      GL_AMD_texture_texture4                           
      GL_AMD_texture_tile_pool                           
      GL_AMD_transform_feedback3_lines_triangles        
      GL_AMD_transform_feedback4                        
      GL_AMD_vertex_shader_layer                        
      GL_AMD_vertex_shader_tessellator                   
      GL_AMD_vertex_shader_viewport_index               
      GL_AMDX_debug_output                              
      GL_AMDX_name_gen_delete                            
      GL_AMDX_random_access_target                       
      GL_AMDX_vertex_shader_tessellator                  
      GL_ANDROID_extension_pack_es31a                    
      GL_ANGLE_depth_texture                             
      GL_ANGLE_framebuffer_blit                          
      GL_ANGLE_framebuffer_multisample                   
      GL_ANGLE_instanced_arrays                          
      GL_ANGLE_pack_reverse_row_order                    
      GL_ANGLE_program_binary                            
      GL_ANGLE_texture_compression_dxt1                  
      GL_ANGLE_texture_compression_dxt3                  
      GL_ANGLE_texture_compression_dxt5                  
      GL_ANGLE_texture_usage                             
      GL_ANGLE_translated_shader_source                  
      GL_APPLE_aux_depth_stencil                         
      GL_APPLE_client_storage                            
      GL_APPLE_copy_texture_levels                       
      GL_APPLE_element_array                             
      GL_APPLE_fence                                     
      GL_APPLE_float_pixels                              
      GL_APPLE_flush_buffer_range                        
      GL_APPLE_flush_render                              
      GL_APPLE_framebuffer_multisample                   
      GL_APPLE_object_purgeable                          
      GL_APPLE_packed_pixel                              
      GL_APPLE_packed_pixels                             
      GL_APPLE_pixel_buffer                              
      GL_APPLE_rgb_422                                   
      GL_APPLE_row_bytes                                 
      GL_APPLE_specular_vector                           
      GL_APPLE_sync                                      
      GL_APPLE_texture_2D_limited_npot                   
      GL_APPLE_texture_format_BGRA8888                   
      GL_APPLE_texture_max_level                         
      GL_APPLE_texture_range                             
      GL_APPLE_transform_hint                            
      GL_APPLE_vertex_array_object                       
      GL_APPLE_vertex_array_range                        
      GL_APPLE_vertex_point_size                         
      GL_APPLE_vertex_program_evaluators                 
      GL_APPLE_ycbcr_422                                 
      GL_ARB_arrays_of_arrays                           
      GL_ARB_base_instance                              
      GL_ARB_bindless_texture                           
      GL_ARB_blend_func_extended                        
      GL_ARB_buffer_storage                             
      GL_ARB_cl_event                                    
      GL_ARB_clear_buffer_object                        
      GL_ARB_clear_texture                              
      GL_ARB_clip_control                               
      GL_ARB_color_buffer_float                         
      GL_ARB_compatibility                              
      GL_ARB_compressed_texture_pixel_storage           
      GL_ARB_compute_shader                             
      GL_ARB_compute_variable_group_size                 
      GL_ARB_conditional_render_inverted                
      GL_ARB_conservative_depth                         
      GL_ARB_context_flush_control                       
      GL_ARB_copy_buffer                                
      GL_ARB_copy_image                                 
      GL_ARB_cull_distance                              
      GL_ARB_debug_group                                 
      GL_ARB_debug_label                                 
      GL_ARB_debug_output                               
      GL_ARB_debug_output2                               
      GL_ARB_depth_buffer_float                         
      GL_ARB_depth_clamp                                
      GL_ARB_depth_texture                              
      GL_ARB_derivative_control                         
      GL_ARB_direct_state_access                        
      GL_ARB_draw_buffers                               
      GL_ARB_draw_buffers_blend                         
      GL_ARB_draw_elements_base_vertex                  
      GL_ARB_draw_indirect                              
      GL_ARB_draw_instanced                             
      GL_ARB_enhanced_layouts                           
      GL_ARB_ES2_compatibility                          
      GL_ARB_ES3_1_compatibility                        
      GL_ARB_ES3_2_compatibility                         
      GL_ARB_ES3_compatibility                          
      GL_ARB_explicit_attrib_location                   
      GL_ARB_explicit_uniform_location                  
      GL_ARB_fragment_coord_conventions                 
      GL_ARB_fragment_layer_viewport                    
      GL_ARB_fragment_program                           
      GL_ARB_fragment_program_shadow                    
      GL_ARB_fragment_shader                            
      GL_ARB_fragment_shader_interlock                   
      GL_ARB_framebuffer_no_attachments                 
      GL_ARB_framebuffer_object                         
      GL_ARB_framebuffer_sRGB                           
      GL_ARB_geometry_shader4                           
      GL_ARB_get_program_binary                         
      GL_ARB_get_texture_sub_image                      
      GL_ARB_gl_spirv                                   
      GL_ARB_gpu_shader_fp64                            
      GL_ARB_gpu_shader_int64                            
      GL_ARB_gpu_shader5                                
      GL_ARB_half_float_pixel                           
      GL_ARB_half_float_vertex                          
      GL_ARB_imaging                                    
      GL_ARB_indirect_parameters                        
      GL_ARB_instanced_arrays                           
      GL_ARB_internalformat_query                       
      GL_ARB_internalformat_query2                      
      GL_ARB_invalidate_subdata                         
      GL_ARB_make_current_read                           
      GL_ARB_map_buffer_alignment                       
      GL_ARB_map_buffer_range                           
      GL_ARB_matrix_palette                              
      GL_ARB_multi_bind                                 
      GL_ARB_multi_draw_indirect                        
      GL_ARB_multisample                                
      GL_ARB_multitexture                               
      GL_ARB_occlusion_query                            
      GL_ARB_occlusion_query2                           
      GL_ARB_parallel_shader_compile                    
      GL_ARB_pipeline_statistics_query                  
      GL_ARB_pixel_buffer_object                        
      GL_ARB_point_parameters                           
      GL_ARB_point_sprite                               
      GL_ARB_polygon_offset_clamp                       
      GL_ARB_post_depth_coverage                         
      GL_ARB_program_interface_query                    
      GL_ARB_provoking_vertex                           
      GL_ARB_query_buffer_object                        
      GL_ARB_robust_buffer_access_behavior              
      GL_ARB_robustness                                  
      GL_ARB_robustness_isolation                        
      GL_ARB_sample_locations                            
      GL_ARB_sample_shading                             
      GL_ARB_sampler_objects                            
      GL_ARB_seamless_cube_map                          
      GL_ARB_seamless_cubemap_per_texture               
      GL_ARB_separate_shader_objects                    
      GL_ARB_shader_atomic_counter_ops                   
      GL_ARB_shader_atomic_counters                     
      GL_ARB_shader_ballot                              
      GL_ARB_shader_bit_encoding                        
      GL_ARB_shader_clock                                
      GL_ARB_shader_draw_parameters                     
      GL_ARB_shader_group_vote                          
      GL_ARB_shader_image_load_store                    
      GL_ARB_shader_image_size                          
      GL_ARB_shader_objects                             
      GL_ARB_shader_precision                           
      GL_ARB_shader_stencil_export                      
      GL_ARB_shader_storage_buffer_object               
      GL_ARB_shader_subroutine                          
      GL_ARB_shader_texture_image_samples               
      GL_ARB_shader_texture_lod                         
      GL_ARB_shader_viewport_layer_array                
      GL_ARB_shading_language_100                       
      GL_ARB_shading_language_120                        
      GL_ARB_shading_language_420pack                   
      GL_ARB_shading_language_include                    
      GL_ARB_shading_language_packing                   
      GL_ARB_shadow                                     
      GL_ARB_shadow_ambient                             
      GL_ARB_sparse_buffer                              
      GL_ARB_sparse_texture                             
      GL_ARB_sparse_texture_clamp                        
      GL_ARB_sparse_texture2                             
      GL_ARB_spirv_extensions                           
      GL_ARB_stencil_texturing                          
      GL_ARB_swap_buffers                                
      GL_ARB_sync                                       
      GL_ARB_tessellation_shader                        
      GL_ARB_texture_barrier                            
      GL_ARB_texture_border_clamp                       
      GL_ARB_texture_buffer_object                      
      GL_ARB_texture_buffer_object_rgb32                
      GL_ARB_texture_buffer_range                       
      GL_ARB_texture_compression                        
      GL_ARB_texture_compression_bptc                   
      GL_ARB_texture_compression_rgtc                   
      GL_ARB_texture_compression_rtgc                    
      GL_ARB_texture_cube_map                           
      GL_ARB_texture_cube_map_array                     
      GL_ARB_texture_env_add                            
      GL_ARB_texture_env_combine                        
      GL_ARB_texture_env_crossbar                       
      GL_ARB_texture_env_dot3                           
      GL_ARB_texture_filter_anisotropic                  
      GL_ARB_texture_filter_minmax                       
      GL_ARB_texture_float                              
      GL_ARB_texture_gather                             
      GL_ARB_texture_mirror_clamp_to_edge               
      GL_ARB_texture_mirrored_repeat                    
      GL_ARB_texture_multisample                        
      GL_ARB_texture_non_power_of_two                   
      GL_ARB_texture_query_levels                       
      GL_ARB_texture_query_lod                          
      GL_ARB_texture_rectangle                          
      GL_ARB_texture_rg                                 
      GL_ARB_texture_rgb10_a2ui                         
      GL_ARB_texture_snorm                              
      GL_ARB_texture_stencil8                           
      GL_ARB_texture_storage                            
      GL_ARB_texture_storage_multisample                
      GL_ARB_texture_swizzle                            
      GL_ARB_texture_view                               
      GL_ARB_timer_query                                
      GL_ARB_transform_feedback_instanced               
      GL_ARB_transform_feedback_overflow_query          
      GL_ARB_transform_feedback2                        
      GL_ARB_transform_feedback3                        
      GL_ARB_transpose_matrix                           
      GL_ARB_uber_buffers                                
      GL_ARB_uber_mem_image                              
      GL_ARB_uber_vertex_array                           
      GL_ARB_uniform_buffer_object                      
      GL_ARB_vertex_array_bgra                          
      GL_ARB_vertex_array_object                        
      GL_ARB_vertex_attrib_64bit                        
      GL_ARB_vertex_attrib_binding                      
      GL_ARB_vertex_blend                                
      GL_ARB_vertex_buffer_object                       
      GL_ARB_vertex_program                             
      GL_ARB_vertex_shader                              
      GL_ARB_vertex_type_10f_11f_11f_rev                
      GL_ARB_vertex_type_2_10_10_10_rev                 
      GL_ARB_viewport_array                             
      GL_ARB_window_pos                                 
      GL_ARM_mali_program_binary                         
      GL_ARM_mali_shader_binary                          
      GL_ARM_rgba8                                       
      GL_ARM_shader_framebuffer_fetch                    
      GL_ARM_shader_framebuffer_fetch_depth_stencil      
      GL_ATI_array_rev_comps_in_4_bytes                  
      GL_ATI_blend_equation_separate                     
      GL_ATI_blend_weighted_minmax                       
      GL_ATI_draw_buffers                               
      GL_ATI_element_array                               
      GL_ATI_envmap_bumpmap                             
      GL_ATI_fragment_shader                            
      GL_ATI_lock_texture                                
      GL_ATI_map_object_buffer                           
      GL_ATI_meminfo                                     
      GL_ATI_pixel_format_float                          
      GL_ATI_pn_triangles                                
      GL_ATI_point_cull_mode                             
      GL_ATI_separate_stencil                           
      GL_ATI_shader_texture_lod                          
      GL_ATI_text_fragment_shader                        
      GL_ATI_texture_compression_3dc                    
      GL_ATI_texture_env_combine3                       
      GL_ATI_texture_float                              
      GL_ATI_texture_mirror_once                        
      GL_ATI_vertex_array_object                         
      GL_ATI_vertex_attrib_array_object                  
      GL_ATI_vertex_blend                                
      GL_ATI_vertex_shader                               
      GL_ATI_vertex_streams                              
      GL_ATIX_pn_triangles                               
      GL_ATIX_texture_env_combine3                       
      GL_ATIX_texture_env_route                          
      GL_ATIX_vertex_shader_output_point_size            
      GL_Autodesk_facet_normal                           
      GL_Autodesk_valid_back_buffer_hint                 
      GL_CR_bounding_box                                 
      GL_CR_cursor_position                              
      GL_CR_head_spu_name                                
      GL_CR_performance_info                             
      GL_CR_print_string                                 
      GL_CR_readback_barrier_size                        
      GL_CR_saveframe                                    
      GL_CR_server_id_sharing                            
      GL_CR_server_matrix                                
      GL_CR_state_parameter                              
      GL_CR_synchronization                              
      GL_CR_tile_info                                    
      GL_CR_tilesort_info                                
      GL_CR_window_size                                  
      GL_DIMD_YUV                                        
      GL_DMP_shader_binary                               
      GL_EXT_422_pixels                                  
      GL_EXT_abgr                                       
      GL_EXT_bgra                                       
      GL_EXT_bindable_uniform                           
      GL_EXT_blend_color                                
      GL_EXT_blend_equation_separate                    
      GL_EXT_blend_func_separate                        
      GL_EXT_blend_logic_op                              
      GL_EXT_blend_minmax                               
      GL_EXT_blend_subtract                             
      GL_EXT_Cg_shader                                   
      GL_EXT_clip_control                                
      GL_EXT_clip_volume_hint                            
      GL_EXT_cmyka                                       
      GL_EXT_color_buffer_float                          
      GL_EXT_color_buffer_half_float                     
      GL_EXT_color_matrix                                
      GL_EXT_color_subtable                              
      GL_EXT_color_table                                 
      GL_EXT_compiled_vertex_array                      
      GL_EXT_convolution                                 
      GL_EXT_convolution_border_modes                    
      GL_EXT_coordinate_frame                            
      GL_EXT_copy_buffer                                
      GL_EXT_copy_image                                  
      GL_EXT_copy_texture                               
      GL_EXT_cull_vertex                                 
      GL_EXT_debug_label                                 
      GL_EXT_debug_marker                                
      GL_EXT_depth_bounds_test                          
      GL_EXT_depth_buffer_float                          
      GL_EXT_direct_state_access                        
      GL_EXT_discard_framebuffer                         
      GL_EXT_disjoint_timer_query                        
      GL_EXT_draw_buffers                                
      GL_EXT_draw_buffers_indexed                        
      GL_EXT_draw_buffers2                              
      GL_EXT_draw_indirect                               
      GL_EXT_draw_instanced                             
      GL_EXT_draw_range_elements                        
      GL_EXT_fog_coord                                  
      GL_EXT_fog_function                                
      GL_EXT_fog_offset                                  
      GL_EXT_frag_depth                                  
      GL_EXT_fragment_lighting                           
      GL_EXT_framebuffer_blit                           
      GL_EXT_framebuffer_multisample                    
      GL_EXT_framebuffer_multisample_blit_scaled         
      GL_EXT_framebuffer_object                         
      GL_EXT_framebuffer_sRGB                           
      GL_EXT_generate_mipmap                             
      GL_EXT_geometry_point_size                         
      GL_EXT_geometry_shader                             
      GL_EXT_geometry_shader4                           
      GL_EXT_glx_stereo_tree                             
      GL_EXT_gpu_program_parameters                     
      GL_EXT_gpu_shader_fp64                             
      GL_EXT_gpu_shader4                                
      GL_EXT_gpu_shader5                                 
      GL_EXT_histogram                                  
      GL_EXT_import_sync_object                          
      GL_EXT_index_array_formats                         
      GL_EXT_index_func                                  
      GL_EXT_index_material                              
      GL_EXT_index_texture                               
      GL_EXT_instanced_arrays                            
      GL_EXT_interlace                                   
      GL_EXT_light_texture                               
      GL_EXT_map_buffer_range                            
      GL_EXT_memory_object                              
      GL_EXT_memory_object_win32                        
      GL_EXT_misc_attribute                              
      GL_EXT_multi_draw_arrays                          
      GL_EXT_multisample                                 
      GL_EXT_multisampled_render_to_texture              
      GL_EXT_multiview_draw_buffers                      
      GL_EXT_occlusion_query_boolean                     
      GL_EXT_packed_depth_stencil                       
      GL_EXT_packed_float                               
      GL_EXT_packed_pixels                              
      GL_EXT_packed_pixels_12                            
      GL_EXT_paletted_texture                            
      GL_EXT_pixel_buffer_object                        
      GL_EXT_pixel_format                                
      GL_EXT_pixel_texture                               
      GL_EXT_pixel_transform                             
      GL_EXT_pixel_transform_color_table                 
      GL_EXT_point_parameters                           
      GL_EXT_polygon_offset                              
      GL_EXT_polygon_offset_clamp                       
      GL_EXT_post_depth_coverage                         
      GL_EXT_primitive_bounding_box                      
      GL_EXT_provoking_vertex                           
      GL_EXT_pvrtc_sRGB                                  
      GL_EXT_raster_multisample                          
      GL_EXT_read_format_bgra                            
      GL_EXT_rescale_normal                             
      GL_EXT_robustness                                  
      GL_EXT_scene_marker                                
      GL_EXT_secondary_color                            
      GL_EXT_semaphore                                  
      GL_EXT_semaphore_win32                            
      GL_EXT_separate_shader_objects                     
      GL_EXT_separate_specular_color                    
      GL_EXT_shader_atomic_counters                      
      GL_EXT_shader_framebuffer_fetch                    
      GL_EXT_shader_image_load_formatted                 
      GL_EXT_shader_image_load_store                    
      GL_EXT_shader_implicit_conversions                 
      GL_EXT_shader_integer_mix                         
      GL_EXT_shader_io_blocks                            
      GL_EXT_shader_pixel_local_storage                  
      GL_EXT_shader_subroutine                           
      GL_EXT_shader_texture_lod                          
      GL_EXT_shadow_funcs                               
      GL_EXT_shadow_samplers                             
      GL_EXT_shared_texture_palette                      
      GL_EXT_sparse_texture2                             
      GL_EXT_sRGB                                        
      GL_EXT_sRGB_write_control                          
      GL_EXT_static_vertex_array                         
      GL_EXT_stencil_clear_tag                           
      GL_EXT_stencil_two_side                            
      GL_EXT_stencil_wrap                               
      GL_EXT_subtexture                                 
      GL_EXT_swap_control                                
      GL_EXT_tessellation_point_size                     
      GL_EXT_tessellation_shader                         
      GL_EXT_texgen_reflection                          
      GL_EXT_texture                                     
      GL_EXT_texture_array                              
      GL_EXT_texture_border_clamp                        
      GL_EXT_texture_buffer                              
      GL_EXT_texture_buffer_object                      
      GL_EXT_texture_buffer_object_rgb32                 
      GL_EXT_texture_color_table                         
      GL_EXT_texture_compression_bptc                   
      GL_EXT_texture_compression_dxt1                    
      GL_EXT_texture_compression_latc                   
      GL_EXT_texture_compression_rgtc                   
      GL_EXT_texture_compression_s3tc                   
      GL_EXT_texture_cube_map                           
      GL_EXT_texture_cube_map_array                      
      GL_EXT_texture_edge_clamp                         
      GL_EXT_texture_env                                 
      GL_EXT_texture_env_add                            
      GL_EXT_texture_env_combine                        
      GL_EXT_texture_env_dot3                           
      GL_EXT_texture_filter_anisotropic                 
      GL_EXT_texture_filter_minmax                       
      GL_EXT_texture_format_BGRA8888                     
      GL_EXT_texture_integer                            
      GL_EXT_texture_lod                                
      GL_EXT_texture_lod_bias                           
      GL_EXT_texture_mirror_clamp                       
      GL_EXT_texture_object                             
      GL_EXT_texture_perturb_normal                      
      GL_EXT_texture_rectangle                          
      GL_EXT_texture_rg                                  
      GL_EXT_texture_shared_exponent                    
      GL_EXT_texture_snorm                              
      GL_EXT_texture_sRGB                               
      GL_EXT_texture_sRGB_decode                        
      GL_EXT_texture_sRGB_R8                            
      GL_EXT_texture_sRGB_RG8                           
      GL_EXT_texture_storage                            
      GL_EXT_texture_swizzle                            
      GL_EXT_texture_type_2_10_10_10_REV                 
      GL_EXT_texture_view                                
      GL_EXT_texture3D                                  
      GL_EXT_texture4D                                   
      GL_EXT_timer_query                                
      GL_EXT_transform_feedback                         
      GL_EXT_transform_feedback2                         
      GL_EXT_transform_feedback3                         
      GL_EXT_unpack_subimage                             
      GL_EXT_vertex_array                               
      GL_EXT_vertex_array_bgra                          
      GL_EXT_vertex_array_set                            
      GL_EXT_vertex_array_setXXX                         
      GL_EXT_vertex_attrib_64bit                        
      GL_EXT_vertex_shader                               
      GL_EXT_vertex_weighting                            
      GL_EXT_win32_keyed_mutex                           
      GL_EXT_window_rectangles                           
      GL_EXT_x11_sync_object                             
      GL_EXTX_framebuffer_mixed_formats                  
      GL_EXTX_packed_depth_stencil                       
      GL_FGL_lock_texture                                
      GL_FJ_shader_binary_GCCSO                          
      GL_GL2_geometry_shader                             
      GL_GREMEDY_frame_terminator                        
      GL_GREMEDY_string_marker                           
      GL_HP_convolution_border_modes                     
      GL_HP_image_transform                              
      GL_HP_occlusion_test                               
      GL_HP_texture_lighting                             
      GL_I3D_argb                                        
      GL_I3D_color_clamp                                 
      GL_I3D_interlace_read                              
      GL_IBM_clip_check                                  
      GL_IBM_cull_vertex                                 
      GL_IBM_load_named_matrix                           
      GL_IBM_multi_draw_arrays                           
      GL_IBM_multimode_draw_arrays                       
      GL_IBM_occlusion_cull                              
      GL_IBM_pixel_filter_hint                           
      GL_IBM_rasterpos_clip                              
      GL_IBM_rescale_normal                              
      GL_IBM_static_data                                 
      GL_IBM_texture_clamp_nodraw                        
      GL_IBM_texture_mirrored_repeat                    
      GL_IBM_vertex_array_lists                          
      GL_IBM_YCbCr                                       
      GL_IMG_multisampled_render_to_texture              
      GL_IMG_program_binary                              
      GL_IMG_read_format                                 
      GL_IMG_sgx_binary                                  
      GL_IMG_shader_binary                               
      GL_IMG_texture_compression_pvrtc                   
      GL_IMG_texture_compression_pvrtc2                  
      GL_IMG_texture_env_enhanced_fixed_function         
      GL_IMG_texture_format_BGRA8888                     
      GL_IMG_user_clip_plane                             
      GL_IMG_vertex_program                              
      GL_INGR_blend_func_separate                        
      GL_INGR_color_clamp                                
      GL_INGR_interlace_read                             
      GL_INGR_multiple_palette                           
      GL_INTEL_coarse_fragment_shader                    
      GL_INTEL_compute_shader_lane_shift                 
      GL_INTEL_conservative_rasterization                
      GL_INTEL_fragment_shader_ordering                  
      GL_INTEL_fragment_shader_span_sharing              
      GL_INTEL_framebuffer_CMAA                          
      GL_INTEL_image_serialize                           
      GL_INTEL_map_texture                               
      GL_INTEL_multi_rate_fragment_shader                
      GL_INTEL_parallel_arrays                           
      GL_INTEL_performance_queries                       
      GL_INTEL_performance_query                         
      GL_INTEL_texture_scissor                           
      GL_KHR_blend_equation_advanced                     
      GL_KHR_blend_equation_advanced_coherent            
      GL_KHR_context_flush_control                      
      GL_KHR_debug                                      
      GL_KHR_no_error                                   
      GL_KHR_parallel_shader_compile                    
      GL_KHR_robust_buffer_access_behavior              
      GL_KHR_robustness                                 
      GL_KHR_texture_compression_astc_hdr                
      GL_KHR_texture_compression_astc_ldr                
      GL_KHR_vulkan_glsl                                 
      GL_KTX_buffer_region                              
      GL_MESA_pack_invert                                
      GL_MESA_program_debug                              
      GL_MESA_resize_buffers                             
      GL_MESA_texture_array                              
      GL_MESA_texture_signed_rgba                        
      GL_MESA_window_pos                                 
      GL_MESA_ycbcr_texture                              
      GL_MESAX_texture_float                             
      GL_MESAX_texture_stack                             
      GL_MTX_fragment_shader                             
      GL_MTX_precision_dpi                               
      GL_NV_3dvision_settings                            
      GL_NV_alpha_test                                   
      GL_NV_alpha_to_coverage_dither_control            
      GL_NV_bgr                                          
      GL_NV_bindless_multi_draw_indirect                 
      GL_NV_bindless_multi_draw_indirect_count           
      GL_NV_bindless_texture                             
      GL_NV_blend_equation_advanced                      
      GL_NV_blend_equation_advanced_coherent             
      GL_NV_blend_minmax                                 
      GL_NV_blend_minmax_factor                          
      GL_NV_blend_square                                
      GL_NV_centroid_sample                              
      GL_NV_clip_space_w_scaling                         
      GL_NV_command_list                                 
      GL_NV_complex_primitives                           
      GL_NV_compute_program5                             
      GL_NV_compute_shader_derivatives                   
      GL_NV_conditional_render                          
      GL_NV_conservative_raster                          
      GL_NV_conservative_raster_dilate                   
      GL_NV_conservative_raster_pre_snap                 
      GL_NV_conservative_raster_pre_snap_triangles       
      GL_NV_conservative_raster_underestimation          
      GL_NV_copy_buffer                                  
      GL_NV_copy_depth_to_color                         
      GL_NV_copy_image                                  
      GL_NV_coverage_sample                              
      GL_NV_deep_texture3D                               
      GL_NV_depth_buffer_float                          
      GL_NV_depth_clamp                                  
      GL_NV_depth_nonlinear                              
      GL_NV_depth_range_unclamped                        
      GL_NV_draw_buffers                                 
      GL_NV_draw_instanced                               
      GL_NV_draw_texture                                 
      GL_NV_draw_vulkan_image                            
      GL_NV_EGL_stream_consumer_external                 
      GL_NV_ES1_1_compatibility                          
      GL_NV_ES3_1_compatibility                          
      GL_NV_evaluators                                   
      GL_NV_explicit_attrib_location                     
      GL_NV_explicit_multisample                        
      GL_NV_fbo_color_attachments                        
      GL_NV_feature_query                                
      GL_NV_fence                                        
      GL_NV_fill_rectangle                               
      GL_NV_float_buffer                                
      GL_NV_fog_distance                                 
      GL_NV_fragdepth                                    
      GL_NV_fragment_coverage_to_color                   
      GL_NV_fragment_program                             
      GL_NV_fragment_program_option                      
      GL_NV_fragment_program2                            
      GL_NV_fragment_program4                            
      GL_NV_fragment_shader_barycentric                  
      GL_NV_fragment_shader_interlock                    
      GL_NV_framebuffer_blit                             
      GL_NV_framebuffer_mixed_samples                    
      GL_NV_framebuffer_multisample                      
      GL_NV_framebuffer_multisample_coverage             
      GL_NV_framebuffer_multisample_ex                   
      GL_NV_generate_mipmap_sRGB                         
      GL_NV_geometry_program4                            
      GL_NV_geometry_shader_passthrough                  
      GL_NV_geometry_shader4                             
      GL_NV_gpu_program_fp64                             
      GL_NV_gpu_program4                                 
      GL_NV_gpu_program4_1                               
      GL_NV_gpu_program5                                 
      GL_NV_gpu_program5_mem_extended                    
      GL_NV_gpu_shader5                                  
      GL_NV_half_float                                  
      GL_NV_instanced_arrays                             
      GL_NV_internalformat_sample_query                  
      GL_NV_light_max_exponent                           
      GL_NV_memory_attachment                            
      GL_NV_mesh_shader                                  
      GL_NV_multisample_coverage                         
      GL_NV_multisample_filter_hint                      
      GL_NV_non_square_matrices                          
      GL_NV_occlusion_query                              
      GL_NV_pack_subimage                                
      GL_NV_packed_depth_stencil                         
      GL_NV_packed_float                                 
      GL_NV_packed_float_linear                          
      GL_NV_parameter_buffer_object                      
      GL_NV_parameter_buffer_object2                     
      GL_NV_path_rendering                               
      GL_NV_path_rendering_shared_edge                   
      GL_NV_pixel_buffer_object                          
      GL_NV_pixel_data_range                             
      GL_NV_platform_binary                              
      GL_NV_point_sprite                                 
      GL_NV_present_video                                
      GL_NV_primitive_restart                           
      GL_NV_query_resource                               
      GL_NV_query_resource_tag                           
      GL_NV_read_buffer                                  
      GL_NV_read_buffer_front                            
      GL_NV_read_depth                                   
      GL_NV_read_depth_stencil                           
      GL_NV_read_stencil                                 
      GL_NV_register_combiners                           
      GL_NV_register_combiners2                          
      GL_NV_representative_fragment_test                 
      GL_NV_robustness_video_memory_purge                
      GL_NV_sample_locations                             
      GL_NV_sample_mask_override_coverage                
      GL_NV_scissor_exclusive                            
      GL_NV_shader_atomic_counters                       
      GL_NV_shader_atomic_float                          
      GL_NV_shader_atomic_float64                        
      GL_NV_shader_atomic_fp16_vector                    
      GL_NV_shader_atomic_int64                         
      GL_NV_shader_buffer_load                           
      GL_NV_shader_buffer_store                          
      GL_NV_shader_storage_buffer_object                 
      GL_NV_shader_texture_footprint                     
      GL_NV_shader_thread_group                          
      GL_NV_shader_thread_shuffle                        
      GL_NV_shading_rate_image                           
      GL_NV_shadow_samplers_array                        
      GL_NV_shadow_samplers_cube                         
      GL_NV_sRGB_formats                                 
      GL_NV_stereo_view_rendering                        
      GL_NV_tessellation_program5                        
      GL_NV_texgen_emboss                                
      GL_NV_texgen_reflection                           
      GL_NV_texture_array                                
      GL_NV_texture_barrier                             
      GL_NV_texture_border_clamp                         
      GL_NV_texture_compression_latc                     
      GL_NV_texture_compression_s3tc                     
      GL_NV_texture_compression_s3tc_update              
      GL_NV_texture_compression_vtc                      
      GL_NV_texture_env_combine4                         
      GL_NV_texture_expand_normal                        
      GL_NV_texture_lod_clamp                            
      GL_NV_texture_multisample                          
      GL_NV_texture_npot_2D_mipmap                       
      GL_NV_texture_rectangle                            
      GL_NV_texture_rectangle_compressed                 
      GL_NV_texture_shader                               
      GL_NV_texture_shader2                              
      GL_NV_texture_shader3                              
      GL_NV_timer_query                                  
      GL_NV_transform_feedback                           
      GL_NV_transform_feedback2                          
      GL_NV_uniform_buffer_unified_memory                
      GL_NV_vdpau_interop                                
      GL_NV_vertex_array_range                           
      GL_NV_vertex_array_range2                          
      GL_NV_vertex_attrib_64bit                          
      GL_NV_vertex_attrib_integer_64bit                  
      GL_NV_vertex_buffer_unified_memory                 
      GL_NV_vertex_program                               
      GL_NV_vertex_program1_1                            
      GL_NV_vertex_program2                              
      GL_NV_vertex_program2_option                       
      GL_NV_vertex_program3                              
      GL_NV_vertex_program4                              
      GL_NV_video_capture                                
      GL_NV_viewport_array2                              
      GL_NV_viewport_swizzle                             
      GL_NVX_blend_equation_advanced_multi_draw_buffers  
      GL_NVX_conditional_render                          
      GL_NVX_flush_hold                                  
      GL_NVX_gpu_memory_info                             
      GL_NVX_instanced_arrays                            
      GL_NVX_multigpu_info                               
      GL_NVX_nvenc_interop                               
      GL_NVX_shader_thread_group                         
      GL_NVX_shader_thread_shuffle                       
      GL_NVX_shared_sync_object                          
      GL_NVX_sysmem_buffer                               
      GL_NVX_ycrcb                                       
      GL_OES_blend_equation_separate                     
      GL_OES_blend_func_separate                         
      GL_OES_blend_subtract                              
      GL_OES_byte_coordinates                            
      GL_OES_compressed_EAC_R11_signed_texture           
      GL_OES_compressed_EAC_R11_unsigned_texture         
      GL_OES_compressed_EAC_RG11_signed_texture          
      GL_OES_compressed_EAC_RG11_unsigned_texture        
      GL_OES_compressed_ETC1_RGB8_texture                
      GL_OES_compressed_ETC2_punchthroughA_RGBA8_texture 
      GL_OES_compressed_ETC2_punchthroughA_sRGB8_alpha_texture 
      GL_OES_compressed_ETC2_RGB8_texture                
      GL_OES_compressed_ETC2_RGBA8_texture               
      GL_OES_compressed_ETC2_sRGB8_alpha8_texture        
      GL_OES_compressed_ETC2_sRGB8_texture               
      GL_OES_compressed_paletted_texture                 
      GL_OES_conditional_query                           
      GL_OES_depth_texture                               
      GL_OES_depth_texture_cube_map                      
      GL_OES_depth24                                     
      GL_OES_depth32                                     
      GL_OES_draw_texture                                
      GL_OES_EGL_image                                  
      GL_OES_EGL_image_external                          
      GL_OES_EGL_sync                                    
      GL_OES_element_index_uint                          
      GL_OES_extended_matrix_palette                     
      GL_OES_fbo_render_mipmap                           
      GL_OES_fixed_point                                 
      GL_OES_fragment_precision_high                     
      GL_OES_framebuffer_object                          
      GL_OES_get_program_binary                          
      GL_OES_mapbuffer                                   
      GL_OES_matrix_get                                  
      GL_OES_matrix_palette                              
      GL_OES_packed_depth_stencil                        
      GL_OES_point_size_array                            
      GL_OES_point_sprite                                
      GL_OES_query_matrix                                
      GL_OES_read_format                                 
      GL_OES_required_internalformat                     
      GL_OES_rgb8_rgba8                                  
      GL_OES_sample_shading                              
      GL_OES_sample_variables                            
      GL_OES_shader_image_atomic                         
      GL_OES_shader_multisample_interpolation            
      GL_OES_single_precision                            
      GL_OES_standard_derivatives                        
      GL_OES_stencil_wrap                                
      GL_OES_stencil1                                    
      GL_OES_stencil4                                    
      GL_OES_stencil8                                    
      GL_OES_surfaceless_context                         
      GL_OES_texture_3D                                  
      GL_OES_texture_compression_astc                    
      GL_OES_texture_cube_map                            
      GL_OES_texture_env_crossbar                        
      GL_OES_texture_float                               
      GL_OES_texture_float_linear                        
      GL_OES_texture_half_float                          
      GL_OES_texture_half_float_linear                   
      GL_OES_texture_mirrored_repeat                     
      GL_OES_texture_npot                                
      GL_OES_texture_stencil8                            
      GL_OES_texture_storage_multisample_2d_array        
      GL_OES_vertex_array_object                         
      GL_OES_vertex_half_float                           
      GL_OES_vertex_type_10_10_10_2                      
      GL_OML_interlace                                   
      GL_OML_resample                                    
      GL_OML_subsample                                   
      GL_OVR_multiview                                   
      GL_OVR_multiview2                                  
      GL_PGI_misc_hints                                  
      GL_PGI_vertex_hints                                
      GL_QCOM_alpha_test                                 
      GL_QCOM_binning_control                            
      GL_QCOM_driver_control                             
      GL_QCOM_extended_get                               
      GL_QCOM_extended_get2                              
      GL_QCOM_perfmon_global_mode                        
      GL_QCOM_tiled_rendering                            
      GL_QCOM_writeonly_rendering                        
      GL_REND_screen_coordinates                         
      GL_S3_performance_analyzer                         
      GL_S3_s3tc                                         
      GL_S3_texture_float_linear                         
      GL_S3_texture_half_float_linear                    
      GL_SGI_color_matrix                                
      GL_SGI_color_table                                 
      GL_SGI_compiled_vertex_array                       
      GL_SGI_cull_vertex                                 
      GL_SGI_index_array_formats                         
      GL_SGI_index_func                                  
      GL_SGI_index_material                              
      GL_SGI_index_texture                               
      GL_SGI_make_current_read                           
      GL_SGI_texture_add_env                             
      GL_SGI_texture_color_table                         
      GL_SGI_texture_edge_clamp                          
      GL_SGI_texture_lod                                 
      GL_SGIS_color_range                                
      GL_SGIS_detail_texture                             
      GL_SGIS_fog_function                               
      GL_SGIS_generate_mipmap                           
      GL_SGIS_multisample                                
      GL_SGIS_multitexture                               
      GL_SGIS_pixel_texture                              
      GL_SGIS_point_line_texgen                          
      GL_SGIS_sharpen_texture                            
      GL_SGIS_texture_border_clamp                       
      GL_SGIS_texture_color_mask                         
      GL_SGIS_texture_edge_clamp                        
      GL_SGIS_texture_filter4                            
      GL_SGIS_texture_lod                               
      GL_SGIS_texture_select                             
      GL_SGIS_texture4D                                  
      GL_SGIX_async                                      
      GL_SGIX_async_histogram                            
      GL_SGIX_async_pixel                                
      GL_SGIX_blend_alpha_minmax                         
      GL_SGIX_clipmap                                    
      GL_SGIX_convolution_accuracy                       
      GL_SGIX_depth_pass_instrument                      
      GL_SGIX_depth_texture                              
      GL_SGIX_flush_raster                               
      GL_SGIX_fog_offset                                 
      GL_SGIX_fog_texture                                
      GL_SGIX_fragment_specular_lighting                 
      GL_SGIX_framezoom                                  
      GL_SGIX_instruments                                
      GL_SGIX_interlace                                  
      GL_SGIX_ir_instrument1                             
      GL_SGIX_list_priority                              
      GL_SGIX_pbuffer                                    
      GL_SGIX_pixel_texture                              
      GL_SGIX_pixel_texture_bits                         
      GL_SGIX_reference_plane                            
      GL_SGIX_resample                                   
      GL_SGIX_shadow                                     
      GL_SGIX_shadow_ambient                             
      GL_SGIX_sprite                                     
      GL_SGIX_subsample                                  
      GL_SGIX_tag_sample_buffer                          
      GL_SGIX_texture_add_env                            
      GL_SGIX_texture_coordinate_clamp                   
      GL_SGIX_texture_lod_bias                           
      GL_SGIX_texture_multi_buffer                       
      GL_SGIX_texture_range                              
      GL_SGIX_texture_scale_bias                         
      GL_SGIX_vertex_preclip                             
      GL_SGIX_vertex_preclip_hint                        
      GL_SGIX_ycrcb                                      
      GL_SGIX_ycrcb_subsample                            
      GL_SUN_convolution_border_modes                    
      GL_SUN_global_alpha                                
      GL_SUN_mesh_array                                  
      GL_SUN_multi_draw_arrays                          
      GL_SUN_read_video_pixels                           
      GL_SUN_slice_accum                                 
      GL_SUN_triangle_list                               
      GL_SUN_vertex                                      
      GL_SUNX_constant_data                              
      GL_VIV_shader_binary                               
      GL_WGL_ARB_extensions_string                       
      GL_WGL_EXT_extensions_string                       
      GL_WGL_EXT_swap_control                            
      GL_WIN_phong_shading                               
      GL_WIN_specular_fog                                
      GL_WIN_swap_hint                                  
      GLU_EXT_nurbs_tessellator                          
      GLU_EXT_object_space_tess                          
      GLU_SGI_filter4_parameters                         
      GLX_AMD_gpu_association                            
      GLX_ARB_create_context                             
      GLX_ARB_create_context_no_error                    
      GLX_ARB_create_context_profile                     
      GLX_ARB_create_context_robustness                  
      GLX_ARB_fbconfig_float                             
      GLX_ARB_framebuffer_sRGB                           
      GLX_ARB_get_proc_address                           
      GLX_ARB_multisample                                
      GLX_ARB_robustness_application_isolation           
      GLX_ARB_robustness_share_group_isolation           
      GLX_ARB_vertex_buffer_object                       
      GLX_EXT_buffer_age                                 
      GLX_EXT_create_context_es_profile                  
      GLX_EXT_create_context_es2_profile                 
      GLX_EXT_fbconfig_packed_float                      
      GLX_EXT_framebuffer_sRGB                           
      GLX_EXT_import_context                             
      GLX_EXT_scene_marker                               
      GLX_EXT_swap_control                               
      GLX_EXT_swap_control_tear                          
      GLX_EXT_texture_from_pixmap                        
      GLX_EXT_visual_info                                
      GLX_EXT_visual_rating                              
      GLX_INTEL_swap_event                               
      GLX_MESA_agp_offset                                
      GLX_MESA_copy_sub_buffer                           
      GLX_MESA_multithread_makecurrent                   
      GLX_MESA_pixmap_colormap                           
      GLX_MESA_query_renderer                            
      GLX_MESA_release_buffers                           
      GLX_MESA_set_3dfx_mode                             
      GLX_MESA_swap_control                              
      GLX_NV_copy_image                                  
      GLX_NV_delay_before_swap                           
      GLX_NV_float_buffer                                
      GLX_NV_multisample_coverage                        
      GLX_NV_present_video                               
      GLX_NV_swap_group                                  
      GLX_NV_video_capture                               
      GLX_NV_video_out                                   
      GLX_NV_video_output                                
      GLX_OML_interlace                                  
      GLX_OML_swap_method                                
      GLX_OML_sync_control                               
      GLX_SGI_cushion                                    
      GLX_SGI_make_current_read                          
      GLX_SGI_swap_control                               
      GLX_SGI_video_sync                                 
      GLX_SGIS_blended_overlay                           
      GLX_SGIS_color_range                               
      GLX_SGIS_multisample                               
      GLX_SGIX_dm_buffer                                 
      GLX_SGIX_fbconfig                                  
      GLX_SGIX_hyperpipe                                 
      GLX_SGIX_pbuffer                                   
      GLX_SGIX_swap_barrier                              
      GLX_SGIX_swap_group                                
      GLX_SGIX_video_resize                              
      GLX_SGIX_video_source                              
      GLX_SGIX_visual_select_group                       
      GLX_SUN_get_transparent_index                      
      GLX_SUN_video_resize                               
      WGL_3DFX_gamma_control                             
      WGL_3DFX_multisample                               
      WGL_3DL_stereo_control                             
      WGL_AMD_gpu_association                           
      WGL_AMDX_gpu_association                           
      WGL_ARB_buffer_region                             
      WGL_ARB_context_flush_control                     
      WGL_ARB_create_context                            
      WGL_ARB_create_context_no_error                   
      WGL_ARB_create_context_profile                    
      WGL_ARB_create_context_robustness                  
      WGL_ARB_extensions_string                         
      WGL_ARB_framebuffer_sRGB                           
      WGL_ARB_make_current_read                         
      WGL_ARB_multisample                               
      WGL_ARB_pbuffer                                   
      WGL_ARB_pixel_format                              
      WGL_ARB_pixel_format_float                        
      WGL_ARB_render_texture                            
      WGL_ARB_robustness_application_isolation           
      WGL_ARB_robustness_share_group_isolation           
      WGL_ATI_pbuffer_memory_hint                        
      WGL_ATI_pixel_format_float                        
      WGL_ATI_render_texture_rectangle                  
      WGL_EXT_buffer_region                              
      WGL_EXT_colorspace                                 
      WGL_EXT_create_context_es_profile                  
      WGL_EXT_create_context_es2_profile                 
      WGL_EXT_depth_float                                
      WGL_EXT_display_color_table                        
      WGL_EXT_extensions_string                         
      WGL_EXT_framebuffer_sRGB                          
      WGL_EXT_framebuffer_sRGBWGL_ARB_create_context     
      WGL_EXT_gamma_control                              
      WGL_EXT_make_current_read                          
      WGL_EXT_multisample                                
      WGL_EXT_pbuffer                                    
      WGL_EXT_pixel_format                               
      WGL_EXT_pixel_format_packed_float                 
      WGL_EXT_render_texture                             
      WGL_EXT_swap_control                              
      WGL_EXT_swap_control_tear                         
      WGL_EXT_swap_interval                              
      WGL_I3D_digital_video_control                      
      WGL_I3D_gamma                                      
      WGL_I3D_genlock                                   
      WGL_I3D_image_buffer                               
      WGL_I3D_swap_frame_lock                            
      WGL_I3D_swap_frame_usage                           
      WGL_INTEL_cl_sharing                               
      WGL_MTX_video_preview                              
      WGL_NV_bridged_display                             
      WGL_NV_copy_image                                  
      WGL_NV_delay_before_swap                           
      WGL_NV_DX_interop                                 
      WGL_NV_DX_interop2                                
      WGL_NV_float_buffer                               
      WGL_NV_gpu_affinity                                
      WGL_NV_multisample_coverage                        
      WGL_NV_present_video                               
      WGL_NV_render_depth_texture                        
      WGL_NV_render_texture_rectangle                    
      WGL_NV_swap_group                                 
      WGL_NV_texture_rectangle                           
      WGL_NV_vertex_array_range                          
      WGL_NV_video_capture                               
      WGL_NV_video_output                                
      WGL_NVX_DX_interop                                 
      WGL_OML_sync_control                               
      WGL_S3_cl_sharingWGL_ARB_create_context_profile    

       :
      RGB DXT1                                          
      RGBA DXT1                                         
      RGBA DXT3                                         
      RGBA DXT5                                         
      RGB FXT1                                           
      RGBA FXT1                                          
      3Dc                                               

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates


--------[ GPGPU ]-------------------------------------------------------------------------------------------------------

  [ Direct3D: AMD Radeon R7 240 Series ]

     :
                                           AMD Radeon R7 240 Series
      PCI-                                    1002-6617 / 1787-2000  (Rev C7)
                                        2025 
                                             aticfx32.dll
                                          26.20.15029.27016
      Shader Model                                      SM 5.0
      Max Threads                                       1024
      Multiple UAV Access                               8 UAVs
      Thread Dispatch                                   3D
      Thread Local Storage                              32 

     :
      10-bit Precision Floating-Point                    
      16-bit Precision Floating-Point                    
      Append/Consume Buffers                            
      Atomic Operations                                 
      Double-Precision Floating-Point                   
      Gather4                                           
      Indirect Compute Dispatch                         
      Map On Default Buffers                             

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates

  [ OpenCL: AMD Radeon R7 240 Series (Oland) ]

     OpenCL:
                                               AMD Accelerated Parallel Processing
                                      Advanced Micro Devices, Inc.
                                         OpenCL 2.1 AMD-APP (3004.8)
                                        Full

     :
                                           Oland
                                            AMD Radeon R7 240 Series
                                            
                                     Advanced Micro Devices, Inc.
                                        OpenCL 1.2 AMD-APP (3004.8)
                                       Full
                                          3004.8
       OpenCL C                                   OpenCL C 1.2 
      Supported SPIR Versions                           1.2
                                                 700 
       /                       5 / 320
      SIMD                         4
       SIMD                                       16
        SIMD                            1
      Wavefront Width                                   64
      Address Space Size                                32 
      Max 2D Image Size                                 16384 x 16384
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Image Array Size                              2048
      Max Image Buffer Size                             134217728
      Max Samplers                                      16
      Max Work-Item Size                                1024 x 1024 x 1024
      Max Work-Group Size                               256
      Max Argument Size                                 1 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            8
      Max Printf Buffer Size                            4 
      Native ISA Vector Widths                          char4, short2, int1, half1, float1, double1
      Preferred Native Vector Widths                    char4, short2, int1, long1, half1, float1, double1
      Host Timer Resolution                             318 ns
      Profiling Timer Resolution                        1 ns
      Profiling Timer Offset Since Epoch                1591423209931156756 ns
      OpenCL DLL                                        opencl.dll (2.2.1.0)

     :
      Global Memory                                     2 
      Free Global Memory                                2046169  / 1816025 
      Global Memory Cache                               16   (Read/Write, 64-byte line)
      Global Memory Channels                            4
      Global Memory Channel Banks                       8
      Global Memory Channel Bank Width                  256 
      Local Memory                                      32 
      Local Memory Size Per Compute Unit                64 
      Local Memory Banks                                32
      Max Memory Object Allocation Size                 1559756 
      Memory Base Address Alignment                     2048 
      Min Data Type Alignment                           128 
      Image Row Pitch Alignment                         256 pixels
      Image Base Address Alignment                      256 pixels

     OpenCL:
      OpenCL 1.1                                          (100%)
      OpenCL 1.2                                          (100%)
      OpenCL 2.0                                          (87%)

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler Available                                
                                          
      Images                                            
      Kernel Execution                                  
      Linker Available                                  
      Little-Endian Device                              
      Native Kernel Execution                            
      Sub-Group Independent Forward Progress             
      SVM Atomics                                        
      SVM Coarse Grain Buffer                            
      SVM Fine Grain Buffer                              
      SVM Fine Grain System                              
      Thread Trace                                       
      Unified Memory                                    

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                 
      Denorms                                            
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

     :
       /                   116 / 24
      cl_altera_compiler_mode                            
      cl_altera_device_temperature                       
      cl_altera_live_object_tracking                     
      cl_amd_bus_addressable_memory                      
      cl_amd_c1x_atomics                                 
      cl_amd_compile_options                             
      cl_amd_copy_buffer_p2p                             
      cl_amd_core_id                                     
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                     
      cl_amd_device_board_name                           
      cl_amd_device_memory_flags                         
      cl_amd_device_persistent_memory                    
      cl_amd_device_profiling_timer_offset               
      cl_amd_device_topology                             
      cl_amd_event_callback                              
      cl_amd_fp64                                       
      cl_amd_hsa                                         
      cl_amd_image2d_from_buffer_read_only               
      cl_amd_liquid_flash                               
      cl_amd_media_ops                                  
      cl_amd_media_ops2                                 
      cl_amd_offline_devices                             
      cl_amd_popcnt                                     
      cl_amd_predefined_macros                           
      cl_amd_printf                                     
      cl_amd_svm                                         
      cl_amd_vec3                                       
      cl_apple_contextloggingfunctions                   
      cl_apple_gl_sharing                                
      cl_apple_setmemobjectdestructor                    
      cl_arm_core_id                                     
      cl_arm_import_memory                               
      cl_arm_import_memory_dma_buf                       
      cl_arm_import_memory_host                          
      cl_arm_integer_dot_product_int8                    
      cl_arm_non_uniform_work_group_size                 
      cl_arm_printf                                      
      cl_arm_thread_limit_hint                           
      cl_ext_atomic_counters_32                          
      cl_ext_atomic_counters_64                          
      cl_ext_device_fission                              
      cl_ext_migrate_memobject                           
      cl_intel_accelerator                               
      cl_intel_advanced_motion_estimation                
      cl_intel_ctz                                       
      cl_intel_d3d11_nv12_media_sharing                  
      cl_intel_device_partition_by_names                 
      cl_intel_device_side_avc_motion_estimation         
      cl_intel_driver_diagnostics                        
      cl_intel_dx9_media_sharing                         
      cl_intel_exec_by_local_thread                      
      cl_intel_media_block_io                            
      cl_intel_motion_estimation                         
      cl_intel_packed_yuv                                
      cl_intel_planar_yuv                                
      cl_intel_printf                                    
      cl_intel_required_subgroup_size                    
      cl_intel_simultaneous_sharing                      
      cl_intel_spirv_device_side_avc_motion_estimation   
      cl_intel_spirv_media_block_io                      
      cl_intel_spirv_subgroups                           
      cl_intel_subgroups                                 
      cl_intel_subgroups_short                           
      cl_intel_thread_local_exec                         
      cl_intel_unified_shared_memory_preview             
      cl_intel_va_api_media_sharing                      
      cl_intel_vec_len_hint                              
      cl_intel_visual_analytics                          
      cl_khr_3d_image_writes                            
      cl_khr_byte_addressable_store                     
      cl_khr_context_abort                               
      cl_khr_create_command_queue                        
      cl_khr_d3d10_sharing                              
      cl_khr_d3d11_sharing                              
      cl_khr_depth_images                                
      cl_khr_dx9_media_sharing                          
      cl_khr_egl_event                                   
      cl_khr_egl_image                                   
      cl_khr_fp16                                        
      cl_khr_fp64                                       
      cl_khr_gl_depth_images                             
      cl_khr_gl_event                                   
      cl_khr_gl_msaa_sharing                             
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                         
      cl_khr_il_program                                  
      cl_khr_image2d_from_buffer                        
      cl_khr_initialize_memory                           
      cl_khr_int64_base_atomics                         
      cl_khr_int64_extended_atomics                     
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_mipmap_image                                
      cl_khr_mipmap_image_writes                         
      cl_khr_priority_hints                              
      cl_khr_select_fprounding_mode                      
      cl_khr_spir                                       
      cl_khr_spirv_no_integer_wrap_decoration            
      cl_khr_srgb_image_writes                           
      cl_khr_subgroups                                   
      cl_khr_terminate_context                           
      cl_khr_throttle_hints                              
      cl_nv_compiler_options                             
      cl_nv_copy_opts                                    
      cl_nv_create_buffer                                
      cl_nv_d3d10_sharing                                
      cl_nv_d3d11_sharing                                
      cl_nv_d3d9_sharing                                 
      cl_nv_device_attribute_query                       
      cl_nv_pragma_unroll                                
      cl_qcom_ext_host_ptr                               
      cl_qcom_ion_host_ptr                               


--------[ Vulkan ]------------------------------------------------------------------------------------------------------

  [ AMD Radeon R7 240 Series ]

     :
                                           AMD Radeon R7 240 Series
                                           Discrete GPU
                                             AMD GCN
      UUID                                    CA-90-98-10-FB-66-13-75-E8-6D-21-00-02-75-48-31
      PCI-                                    1002-6617
                                           2 
      Max 1D Image Size                                 16384
      Max 2D Image Size                                 16384 x 16384
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Cube Image Size                               16384 x 16384
      Max Image Layers                                  2048
      Max Texel Buffer Elements                         4294967295
      Max Uniform Buffer Range                          4294967295
      Max Storage Buffer Range                          4294967295
      Max Push Constants Size                           128 
      Max Memory Allocation Count                       4096
      Max Sampler Allocation Count                      1048576
      Buffer Image Granularity                          1 
      Sparse Address Space Size                         1086626725888 
      Max Bound Descriptor Sets                         32
      Max Per-Stage Descriptor Samplers                 4294967295
      Max Per-Stage Descriptor Uniform Buffers          4294967295
      Max Per-Stage Descriptor Storage Buffers          4294967295
      Max Per-Stage Descriptor Sampled Images           4294967295
      Max Per-Stage Descriptor Storage Images           4294967295
      Max Per-Stage Descriptor Input Attachments        4294967295
      Max Per-Stage Resources                           4294967295
      Max Descriptor Set Samplers                       4294967295
      Max Descriptor Set Uniform Buffers                4294967295
      Max Descriptor Set Dynamic Uniform Buffers        8
      Max Descriptor Set Storage Buffers                4294967295
      Max Descriptor Set Dynamic Storage Buffers        8
      Max Descriptor Set Sampled Images                 4294967295
      Max Descriptor Set Storage Images                 4294967295
      Max Descriptor Set Input Attachments              4294967295
      Max Vertex Input Attributes                       64
      Max Vertex Input Bindings                         32
      Max Vertex Input Attribute Offset                 4294967295
      Max Vertex Input Binding Stride                   16383
      Max Vertex Output Components                      128
      Max Tesselation Generation Level                  64
      Max Tesselation Patch Size                        32
      Max Tesselation Control Per-Vertex Input Components128
      Max Tesselation Control Per-Vertex Output Components128
      Max Tesselation Control Per-Patch Output Components120
      Max Tesselation Control Total Output Components   4096
      Max Tesselation Evaluation Input Components       128
      Max Tesselation Evaluation Output Components      128
      Max Geometry Shader Invocations                   127
      Max Geometry Input Components                     128
      Max Geometry Output Components                    128
      Max Geometry Output Vertices                      1024
      Max Geometry Total Output Components              16384
      Max Fragment Input Components                     128
      Max Fragment Output Attachments                   8
      Max Fragment DualSrc Attachments                  1
      Max Fragment Combined Output Resources            4294967295
      Max Compute Shared Memory Size                    32768 
      Max Compute Work Group Count                      X: 65535, Y: 65535, Z: 65535
      Max Compute Work Group Invocations                1024
      Max Compute Work Group Size                       X: 1024, Y: 1024, Z: 1024
      Subpixel Precision Bits                           8
      Subtexel Precision Bits                           8
      Mipmap Precision Bits                             8
      Max Draw Indexed Index Value                      4294967295
      Max Draw Indirect Count                           4294967295
      Max Sampler LOD Bias                              15.996094
      Max Sampler Anisotropy                            16.000000
      Max Viewports                                     16
      Max Viewport Size                                 16384 x 16384
      Viewport Bounds Range                             -32768.000000 ... 32767.000000
      Viewport Subpixel Bits                            8
      Min Memory Map Alignment                          64 
      Min Texel Buffer Offset Alignment                 4 
      Min Uniform Buffer Offset Alignment               16 
      Min Storage Buffer Offset Alignment               4 
      Min / Max Texel Offset                            -64 / 63
      Min / Max Texel Gather Offset                     -32 / 31
      Min / Max Interpolation Offset                    -2.000000 / 2.000000
      Subpixel Interpolation Offset Bits                8
      Max Framebuffer Size                              16384 x 16384
      Max Framebuffer Layers                            2048
      Framebuffer Color Sample Counts                   0x0000000F
      Framebuffer Depth Sample Counts                   0x0000000F
      Framebuffer Stencil Sample Counts                 0x0000000F
      Framebuffer No Attachments Sample Counts          0x0000000F
      Max Color Attachments                             8
      Sampled Image Color Sample Counts                 0x0000000F
      Sampled Image Integer Sample Counts               0x0000000F
      Sampled Image Depth Sample Counts                 0x0000000F
      Sampled Image Stencil Sample Counts               0x0000000F
      Storage Image Sample Counts                       0x0000000F
      Max Sample Mask Words                             1
      Timestamp Period                                  37.037037 ns
      Max Clip Distances                                8
      Max Cull Distances                                8
      Max Combined Clip and Cull Distances              8
      Discrete Queue Priorities                         2
      Point Size Range                                  0.000000 ... 8191.875000
      Line Width Range                                  0.000000 ... 8191.875000
      Point Size Granularity                            0.125000
      Line Width Granularity                            0.125000
      Optimal Buffer Copy Offset Alignment              1 
      Optimal Buffer Copy Row Pitch Alignment           1 
      Non-Coherent Atom Size                            128 
                                          2.0.137
       API                                        1.2.133
      Vulkan DLL                                        C:\Windows\SysWow64\amdvlk32.dll (9.2.10.137)

     :
      Alpha To One                                       
      Anisotropic Filtering                             
      ASTC LDR Texture Compression                       
      BC Texture Compression                            
      Depth Bias Clamping                               
      Depth Bounds Tests                                
      Depth Clamping                                    
      Draw Indirect First Instance                      
      Dual Source Blend Operations                      
      ETC2 and EAC Texture Compression                   
      Fragment Stores and Atomics                       
      Full Draw Index Uint32                            
      Geometry Shader                                   
      Image Cube Array                                  
      Independent Blend                                 
      Inherited Queries                                 
      Large Points                                      
      Logic Operations                                  
      Multi-Draw Indirect                               
      Multi Viewport                                    
      Occlusion Query Precise                           
      Pipeline Statistics Query                         
      Point and Wireframe Fill Modes                    
      Robust Buffer Access                              
      Sample Rate Shading                               
      Shader Clip Distance                              
      Shader Cull Distance                              
      Shader Float64                                    
      Shader Image Gather Extended                      
      Shader Int16                                       
      Shader Int64                                      
      Shader Resource Min LOD                           
      Shader Resource Residency                         
      Shader Sampled Image Array Dynamic Indexing       
      Shader Storage Buffer Array Dynamic Indexing      
      Shader Storage Image Array Dynamic Indexing       
      Shader Storage Image Extended Formats             
      Shader Storage Image Multisample                  
      Shader Storage Image Read Without Format          
      Shader Storage Image Write Without Format         
      Shader Tesselation and Geometry Point Size        
      Shader Uniform Buffer Array Dynamic Indexing      
      Sparse Binding                                    
      Sparse Residency 2 Samples                         
      Sparse Residency 4 Samples                         
      Sparse Residency 8 Samples                         
      Sparse Residency 16 Samples                        
      Sparse Residency Aliased                           
      Sparse Residency Aligned Mip Size                 
      Sparse Residency Buffer                           
      Sparse Residency Image 2D                         
      Sparse Residency Image 3D                          
      Sparse Residency Non-Resident Strict              
      Sparse Residency Standard 2D Block Shape          
      Sparse Residency Standard 2D Multisample Block Shape
      Sparse Residency Standard 3D Block Shape          
      Standard Sample Locations                         
      Strict Line Rasterization                         
      Tesselation Shader                                
      Timestamps on All Graphics and Compute Queues     
      Variable Multisample Rate                         
      Vertex Pipeline Stores and Atomics                
      Wide Lines                                        

    Queue:
      Queue Count                                       1
      Timestamp Valid Bits                              64
      Min Image Transfer Granularity                    1 x 1 x 1
      Compute Operations                                
      Graphics Operations                               
      Sparse Memory Management Operations               
      Transfer Operations                               

    Queue:
      Queue Count                                       2
      Timestamp Valid Bits                              64
      Min Image Transfer Granularity                    1 x 1 x 1
      Compute Operations                                
      Graphics Operations                                
      Sparse Memory Management Operations                
      Transfer Operations                               

    Queue:
      Queue Count                                       2
      Timestamp Valid Bits                              0
      Min Image Transfer Granularity                    8 x 8 x 1
      Compute Operations                                 
      Graphics Operations                                
      Sparse Memory Management Operations                
      Transfer Operations                               

    Memory Heap:
      Heap Type                                         
      Heap Size                                         1792 
      Host Cached                                       
      Host Coherent                                     
      Host Visible                                      
      Lazily Allocated                                  

    Memory Heap:
      Heap Type                                         
      Heap Size                                         3839 
      Host Cached                                       
      Host Coherent                                     
      Host Visible                                      
      Lazily Allocated                                  

    Memory Heap:
      Heap Type                                         
      Heap Size                                         256 
      Host Cached                                       
      Host Coherent                                     
      Host Visible                                      
      Lazily Allocated                                  

     :
      VK_AMD_buffer_marker                              
      VK_AMD_calibrated_timestamps                      
      VK_AMD_display_native_hdr                         
      VK_AMD_draw_indirect_count                        
      VK_AMD_gcn_shader                                 
      VK_AMD_gpa_interface                              
      VK_AMD_memory_overallocation_behavior             
      VK_AMD_mixed_attachment_samples                   
      VK_AMD_negative_viewport_height                   
      VK_AMD_pipeline_compiler_control                  
      VK_AMD_shader_ballot                              
      VK_AMD_shader_core_properties                     
      VK_AMD_shader_core_properties2                    
      VK_AMD_shader_explicit_vertex_parameter           
      VK_AMD_shader_fragment_mask                       
      VK_AMD_shader_image_load_store_lod                
      VK_AMD_shader_info                                
      VK_AMD_shader_trinary_minmax                      
      VK_AMD_texture_gather_bias_lod                    
      VK_AMD_wave_limits                                
      VK_EXT_calibrated_timestamps                      
      VK_EXT_depth_clip_enable                          
      VK_EXT_depth_range_unrestricted                   
      VK_EXT_descriptor_indexing                        
      VK_EXT_external_memory_host                       
      VK_EXT_full_screen_exclusive                      
      VK_EXT_global_priority                            
      VK_EXT_hdr_metadata                               
      VK_EXT_host_query_reset                           
      VK_EXT_inline_uniform_block                       
      VK_EXT_line_rasterization                         
      VK_EXT_memory_budget                              
      VK_EXT_memory_priority                            
      VK_EXT_pipeline_creation_cache_control            
      VK_EXT_pipeline_creation_feedback                 
      VK_EXT_queue_family_foreign                       
      VK_EXT_sample_locations                           
      VK_EXT_sampler_filter_minmax                      
      VK_EXT_scalar_block_layout                        
      VK_EXT_separate_stencil_usage                     
      VK_EXT_shader_demote_to_helper_invocation         
      VK_EXT_shader_stencil_export                      
      VK_EXT_shader_subgroup_ballot                     
      VK_EXT_shader_subgroup_vote                       
      VK_EXT_shader_viewport_index_layer                
      VK_EXT_subgroup_size_control                      
      VK_EXT_texel_buffer_alignment                     
      VK_EXT_tooling_info                               
      VK_EXT_transform_feedback                         
      VK_EXT_vertex_attribute_divisor                   
      VK_GOOGLE_decorate_string                         
      VK_GOOGLE_hlsl_functionality1                     
      VK_KHR_16bit_storage                              
      VK_KHR_8bit_storage                               
      VK_KHR_bind_memory2                               
      VK_KHR_create_renderpass2                         
      VK_KHR_dedicated_allocation                       
      VK_KHR_depth_stencil_resolve                      
      VK_KHR_descriptor_update_template                 
      VK_KHR_device_group                               
      VK_KHR_draw_indirect_count                        
      VK_KHR_driver_properties                          
      VK_KHR_external_fence                             
      VK_KHR_external_fence_win32                       
      VK_KHR_external_memory                            
      VK_KHR_external_memory_win32                      
      VK_KHR_external_semaphore                         
      VK_KHR_external_semaphore_win32                   
      VK_KHR_get_memory_requirements2                   
      VK_KHR_image_format_list                          
      VK_KHR_imageless_framebuffer                      
      VK_KHR_maintenance1                               
      VK_KHR_maintenance2                               
      VK_KHR_maintenance3                               
      VK_KHR_multiview                                  
      VK_KHR_pipeline_executable_properties             
      VK_KHR_relaxed_block_layout                       
      VK_KHR_sampler_mirror_clamp_to_edge               
      VK_KHR_separate_depth_stencil_layouts             
      VK_KHR_shader_atomic_int64                        
      VK_KHR_shader_clock                               
      VK_KHR_shader_draw_parameters                     
      VK_KHR_shader_float_controls                      
      VK_KHR_shader_float16_int8                        
      VK_KHR_shader_non_semantic_info                   
      VK_KHR_shader_subgroup_extended_types             
      VK_KHR_spirv_1_4                                  
      VK_KHR_storage_buffer_storage_class               
      VK_KHR_swapchain                                  
      VK_KHR_swapchain_mutable_format                   
      VK_KHR_timeline_semaphore                         
      VK_KHR_uniform_buffer_standard_layout             
      VK_KHR_variable_pointers                          
      VK_KHR_vulkan_memory_model                        
      VK_KHR_win32_keyed_mutex                          

    Instance Extensions:
      VK_EXT_debug_report                               
      VK_EXT_debug_utils                                
      VK_EXT_swapchain_colorspace                       
      VK_KHR_device_group_creation                      
      VK_KHR_external_fence_capabilities                
      VK_KHR_external_memory_capabilities               
      VK_KHR_external_semaphore_capabilities            
      VK_KHR_get_physical_device_properties2            
      VK_KHR_get_surface_capabilities2                  
      VK_KHR_surface                                    
      VK_KHR_win32_surface                              

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates


--------[  ]------------------------------------------------------------------------------------------------------

    @Batang                                   Roman       Regular                      16 x 32   40 %
    @Batang                                   Roman       Regular                       16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                   16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                         16 x 32   40 %
    @Batang                                   Roman       Regular           16 x 32   40 %
    @BatangChe                                Modern      Regular                      16 x 32   40 %
    @BatangChe                                Modern      Regular                       16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                   16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                         16 x 32   40 %
    @BatangChe                                Modern      Regular           16 x 32   40 %
    @DFKai-SB                                 Script      Regular                        16 x 32   40 %
    @DFKai-SB                                 Script      Regular         (BIG5)        16 x 32   40 %
    @Dotum                                    Swiss       Regular                      16 x 32   40 %
    @Dotum                                    Swiss       Regular                       16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                   16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                         16 x 32   40 %
    @Dotum                                    Swiss       Regular           16 x 32   40 %
    @DotumChe                                 Modern      Regular                      16 x 32   40 %
    @DotumChe                                 Modern      Regular                       16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                   16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                         16 x 32   40 %
    @DotumChe                                 Modern      Regular           16 x 32   40 %
    @FangSong                                 Modern                              16 x 32   40 %
    @FangSong                                 Modern               (2312)        16 x 32   40 %
    @Gulim                                    Swiss       Regular                      16 x 32   40 %
    @Gulim                                    Swiss       Regular                       16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                   16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                         16 x 32   40 %
    @Gulim                                    Swiss       Regular           16 x 32   40 %
    @GulimChe                                 Modern      Regular                      16 x 32   40 %
    @GulimChe                                 Modern      Regular                       16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                   16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                         16 x 32   40 %
    @GulimChe                                 Modern      Regular           16 x 32   40 %
    @Gungsuh                                  Roman       Regular                      16 x 32   40 %
    @Gungsuh                                  Roman       Regular                       16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                   16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                         16 x 32   40 %
    @Gungsuh                                  Roman       Regular           16 x 32   40 %
    @GungsuhChe                               Modern      Regular                      16 x 32   40 %
    @GungsuhChe                               Modern      Regular                       16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                   16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                         16 x 32   40 %
    @GungsuhChe                               Modern      Regular           16 x 32   40 %
    @KaiTi                                    Modern                              16 x 32   40 %
    @KaiTi                                    Modern               (2312)        16 x 32   40 %
    @Malgun Gothic                            Swiss       Regular                        15 x 43   40 %
    @Malgun Gothic                            Swiss       Regular                         15 x 43   40 %
    @Meiryo UI                                Swiss                             17 x 41   40 %
    @Meiryo UI                                Swiss                              17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                          17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                  17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo                                   Swiss                             31 x 48   40 %
    @Meiryo                                   Swiss                              31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                          31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                  31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Microsoft JhengHei                       Swiss                              15 x 43   40 %
    @Microsoft JhengHei                       Swiss                               15 x 43   40 %
    @Microsoft JhengHei                       Swiss                (BIG5)        15 x 43   40 %
    @Microsoft YaHei                          Swiss                              15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                          15 x 42   40 %
    @Microsoft YaHei                          Swiss                (2312)        15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                  15 x 42   40 %
    @MingLiU_HKSCS                            Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU                                  Modern      Regular                        16 x 32   40 %
    @MingLiU                                  Modern      Regular         (BIG5)        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    @MS Gothic                                Modern      Regular                      16 x 32   40 %
    @MS Gothic                                Modern      Regular                       16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular                   16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular           16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                      16 x 32   40 %
    @MS Mincho                                Modern      Regular                       16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                   16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular           16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS PGothic                               Swiss       Regular                      13 x 32   40 %
    @MS PGothic                               Swiss       Regular                       13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular                   13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular           13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                      13 x 32   40 %
    @MS PMincho                               Roman       Regular                       13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                   13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular           13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                      13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                       13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                   13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular           13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @NSimSun                                  Modern      Regular                        16 x 32   40 %
    @NSimSun                                  Modern      Regular         (2312)        16 x 32   40 %
    @PMingLiU                                 Roman       Regular                        16 x 32   40 %
    @PMingLiU                                 Roman       Regular         (BIG5)        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular                        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular         (BIG5)        16 x 32   40 %
    @SimHei                                   Modern                              16 x 32   40 %
    @SimHei                                   Modern               (2312)        16 x 32   40 %
    @SimSun                                   Special     Regular                        16 x 32   40 %
    @SimSun                                   Special     Regular         (2312)        16 x 32   40 %
    @SimSun-ExtB                              Modern                              16 x 32   40 %
    @SimSun-ExtB                              Modern               (2312)        16 x 32   40 %
    Aharoni                                   Special                             15 x 32   70 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Angsana New                               Roman                                8 x 43   40 %
    Angsana New                               Roman                                 8 x 43   40 %
    AngsanaUPC                                Roman                                8 x 43   40 %
    AngsanaUPC                                Roman                                 8 x 43   40 %
    Aparajita                                 Swiss       Regular                        16 x 38   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                             9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                  9 x 36   40 %
    Arial Black                               Swiss                             18 x 45   90 %
    Arial Black                               Swiss                              18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                          18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                  18 x 45   90 %
    Arial Unicode MS                          Special     Regular                      28 x 36   40 %
    Arial Unicode MS                          Special     Regular                     28 x 36   40 %
    Arial Unicode MS                          Special     Regular                       28 x 36   40 %
    Arial Unicode MS                          Special     Regular                        28 x 36   40 %
    Arial Unicode MS                          Special     Regular                           28 x 36   40 %
    Arial Unicode MS                          Special     Regular                   28 x 36   40 %
    Arial Unicode MS                          Special     Regular                        28 x 36   40 %
    Arial Unicode MS                          Special     Regular           28 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                             14 x 36   40 %
    Arial                                     Swiss                            14 x 36   40 %
    Arial                                     Swiss                              14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                                  14 x 36   40 %
    Arial                                     Swiss                          14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                  14 x 36   40 %
    Batang                                    Roman       Regular                      16 x 32   40 %
    Batang                                    Roman       Regular                       16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                   16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                         16 x 32   40 %
    Batang                                    Roman       Regular           16 x 32   40 %
    BatangChe                                 Modern      Regular                      16 x 32   40 %
    BatangChe                                 Modern      Regular                       16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                   16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                         16 x 32   40 %
    BatangChe                                 Modern      Regular           16 x 32   40 %
    Browallia New                             Swiss       Regular                         9 x 40   40 %
    Browallia New                             Swiss       Regular                          9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                         9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                          9 x 40   40 %
    Calibri Light                             Swiss       Italic                       17 x 39   30 %
    Calibri Light                             Swiss       Italic                      17 x 39   30 %
    Calibri Light                             Swiss       Italic                        17 x 39   30 %
    Calibri Light                             Swiss       Italic                         17 x 39   30 %
    Calibri Light                             Swiss       Italic                    17 x 39   30 %
    Calibri Light                             Swiss       Italic                         17 x 39   30 %
    Calibri Light                             Swiss       Italic            17 x 39   30 %
    Calibri                                   Swiss       Regular                      17 x 39   40 %
    Calibri                                   Swiss       Regular                     17 x 39   40 %
    Calibri                                   Swiss       Regular                       17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular                   17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular           17 x 39   40 %
    Cambria Math                              Roman       Regular                      20 x 179   40 %
    Cambria Math                              Roman       Regular                     20 x 179   40 %
    Cambria Math                              Roman       Regular                       20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular                   20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular           20 x 179   40 %
    Cambria                                   Roman       Regular                      20 x 38   40 %
    Cambria                                   Roman       Regular                     20 x 38   40 %
    Cambria                                   Roman       Regular                       20 x 38   40 %
    Cambria                                   Roman       Regular                        20 x 38   40 %
    Cambria                                   Roman       Regular                   20 x 38   40 %
    Cambria                                   Roman       Regular                        20 x 38   40 %
    Cambria                                   Roman       Regular           20 x 38   40 %
    Candara                                   Swiss       Regular                      17 x 39   40 %
    Candara                                   Swiss       Regular                     17 x 39   40 %
    Candara                                   Swiss       Regular                       17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular                   17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular           17 x 39   40 %
    Comic Sans MS                             Script                            15 x 45   40 %
    Comic Sans MS                             Script                             15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                         15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                 15 x 45   40 %
    Consolas                                  Modern      Regular                      18 x 37   40 %
    Consolas                                  Modern      Regular                     18 x 37   40 %
    Consolas                                  Modern      Regular                       18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular                   18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular           18 x 37   40 %
    Constantia                                Roman       Regular                      17 x 39   40 %
    Constantia                                Roman       Regular                     17 x 39   40 %
    Constantia                                Roman       Regular                       17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular                   17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular           17 x 39   40 %
    Corbel                                    Swiss       Regular                      17 x 39   40 %
    Corbel                                    Swiss       Regular                     17 x 39   40 %
    Corbel                                    Swiss       Regular                       17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular                   17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular           17 x 39   40 %
    Cordia New                                Swiss       Regular                         9 x 44   40 %
    Cordia New                                Swiss       Regular                          9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                         9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                          9 x 44   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                            19 x 36   40 %
    Courier New                               Modern                           19 x 36   40 %
    Courier New                               Modern                             19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                                 19 x 36   40 %
    Courier New                               Modern                         19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                 19 x 36   40 %
    Courier                                   Roman                                  8 x 13   40 %
    Cuprum                                    Special     Bold                         15 x 37   70 %
    Cuprum                                    Special     Bold                           15 x 37   70 %
    Cuprum                                    Special     Bold                      15 x 37   70 %
    Cuprum                                    Special     Bold                           15 x 37   70 %
    DamageLog                                 Special     Regular                        20 x 33   40 %
    DaunPenh                                  Special                             12 x 43   40 %
    David                                     Swiss       Regular                           13 x 31   40 %
    DFKai-SB                                  Script      Regular                        16 x 32   40 %
    DFKai-SB                                  Script      Regular         (BIG5)        16 x 32   40 %
    DilleniaUPC                               Roman                                9 x 42   40 %
    DilleniaUPC                               Roman                                 9 x 42   40 %
    DokChampa                                 Swiss                               19 x 62   40 %
    DokChampa                                 Swiss                                19 x 62   40 %
    Dotum                                     Swiss       Regular                      16 x 32   40 %
    Dotum                                     Swiss       Regular                       16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                   16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                         16 x 32   40 %
    Dotum                                     Swiss       Regular           16 x 32   40 %
    DotumChe                                  Modern      Regular                      16 x 32   40 %
    DotumChe                                  Modern      Regular                       16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                   16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                         16 x 32   40 %
    DotumChe                                  Modern      Regular           16 x 32   40 %
    Ebrima                                    Special                           19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                19 x 43   40 %
    Enigmatic Unicode                         Special     Regular                       14 x 39   40 %
    Enigmatic Unicode                         Special     Regular                        14 x 39   40 %
    Enigmatic Unicode                         Special     Regular                   14 x 39   40 %
    Enigmatic Unicode                         Special     Regular           14 x 39   40 %
    Estrangelo Edessa                         Script                              16 x 36   40 %
    EucrosiaUPC                               Roman                                9 x 39   40 %
    EucrosiaUPC                               Roman                                 9 x 39   40 %
    Euphemia                                  Swiss       Regular                        22 x 42   40 %
    FangSong                                  Modern                              16 x 32   40 %
    FangSong                                  Modern               (2312)        16 x 32   40 %
    Fixedsys                                  Swiss                                  8 x 16   40 %
    Franklin Gothic Medium                    Swiss                             14 x 36   40 %
    Franklin Gothic Medium                    Swiss                              14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                          14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                  14 x 36   40 %
    FrankRuehl                                Swiss       Regular                           13 x 30   40 %
    FreesiaUPC                                Swiss       Regular                         9 x 38   40 %
    FreesiaUPC                                Swiss       Regular                          9 x 38   40 %
    Gabriola                                  Decorative  Regular                      16 x 59   40 %
    Gabriola                                  Decorative  Regular                       16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular                   16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular           16 x 59   40 %
    Gautami                                   Swiss       Regular                        18 x 56   40 %
    Georgia                                   Roman                             14 x 36   40 %
    Georgia                                   Roman                              14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                          14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                  14 x 36   40 %
    Gisha                                     Swiss                               16 x 38   40 %
    Gisha                                     Swiss                                  16 x 38   40 %
    Gulim                                     Swiss       Regular                      16 x 32   40 %
    Gulim                                     Swiss       Regular                       16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                   16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                         16 x 32   40 %
    Gulim                                     Swiss       Regular           16 x 32   40 %
    GulimChe                                  Modern      Regular                      16 x 32   40 %
    GulimChe                                  Modern      Regular                       16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                   16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                         16 x 32   40 %
    GulimChe                                  Modern      Regular           16 x 32   40 %
    Gungsuh                                   Roman       Regular                      16 x 32   40 %
    Gungsuh                                   Roman       Regular                       16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                   16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                         16 x 32   40 %
    Gungsuh                                   Roman       Regular           16 x 32   40 %
    GungsuhChe                                Modern      Regular                      16 x 32   40 %
    GungsuhChe                                Modern      Regular                       16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                   16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                         16 x 32   40 %
    GungsuhChe                                Modern      Regular           16 x 32   40 %
    Gunplay                                   Swiss       Regular                        16 x 39   40 %
    Gunplay                                   Swiss       Regular                        16 x 39   40 %
    Gunplay                                   Swiss       Regular           16 x 39   40 %
    Impact                                    Swiss                             13 x 39   40 %
    Impact                                    Swiss                              13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                          13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                  13 x 39   40 %
    IrisUPC                                   Swiss       Regular                         9 x 40   40 %
    IrisUPC                                   Swiss       Regular                          9 x 40   40 %
    Iskoola Pota                              Swiss                               22 x 36   40 %
    JasmineUPC                                Roman       Regular                         9 x 34   40 %
    JasmineUPC                                Roman       Regular                          9 x 34   40 %
    KaiTi                                     Modern                              16 x 32   40 %
    KaiTi                                     Modern               (2312)        16 x 32   40 %
    Kalinga                                   Swiss       Regular                        19 x 48   40 %
    Kartika                                   Roman       Regular                        27 x 46   40 %
    Khmer UI                                  Swiss                               21 x 36   40 %
    KodchiangUPC                              Roman       Regular                         9 x 31   40 %
    KodchiangUPC                              Roman       Regular                          9 x 31   40 %
    Kokila                                    Swiss       Regular                        13 x 37   40 %
    Lao UI                                    Swiss                               18 x 43   40 %
    Latha                                     Swiss       Regular                        23 x 44   40 %
    Leelawadee                                Swiss                               17 x 38   40 %
    Leelawadee                                Swiss                                17 x 38   40 %
    Levenim MT                                Special     Regular                           16 x 42   40 %
    LilyUPC                                   Swiss                                9 x 30   40 %
    LilyUPC                                   Swiss                                 9 x 30   40 %
    Lucida Console                            Modern                             19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                         19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                 19 x 32   40 %
    Lucida Sans Unicode                       Swiss                             16 x 49   40 %
    Lucida Sans Unicode                       Swiss                              16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                                  16 x 49   40 %
    Lucida Sans Unicode                       Swiss                          16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                  16 x 49   40 %
    Malgun Gothic                             Swiss       Regular                        15 x 43   40 %
    Malgun Gothic                             Swiss       Regular                         15 x 43   40 %
    Mangal                                    Roman       Regular                        19 x 54   40 %
    Marlett                                   Special     Regular                      31 x 32   50 %
    Meiryo UI                                 Swiss                             17 x 41   40 %
    Meiryo UI                                 Swiss                              17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                          17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                  17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo                                    Swiss                             31 x 48   40 %
    Meiryo                                    Swiss                              31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                          31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                  31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Micra                                     Special     Normal                         27 x 33   40 %
    Micra                                     Special     Normal                    27 x 33   40 %
    MicraC                                    Special     Regular                   26 x 32   40 %
    MicraDi                                   Special     Regular                      22 x 35   40 %
    MicraDi                                   Special     Regular                       22 x 35   40 %
    MicraDi                                   Special     Regular                        22 x 35   40 %
    MicraDi                                   Special     Regular                   22 x 35   40 %
    MicraDi                                   Special     Regular                        22 x 35   40 %
    MicraDi                                   Special     Regular           22 x 35   40 %
    Micramaxnorm                              Special     Normal                         26 x 33   40 %
    Micramaxnorm                              Special     Normal                    26 x 33   40 %
    Microsoft Himalaya                        Special                             13 x 32   40 %
    Microsoft JhengHei                        Swiss                              15 x 43   40 %
    Microsoft JhengHei                        Swiss                               15 x 43   40 %
    Microsoft JhengHei                        Swiss                (BIG5)        15 x 43   40 %
    Microsoft New Tai Lue                     Swiss       Regular                        19 x 42   40 %
    Microsoft PhagsPa                         Swiss       Regular                        24 x 41   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                             14 x 36   40 %
    Microsoft Sans Serif                      Swiss                            14 x 36   40 %
    Microsoft Sans Serif                      Swiss                              14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss                          14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                  14 x 36   40 %
    Microsoft Tai Le                          Swiss       Regular                        19 x 41   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft YaHei                           Swiss                              15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                          15 x 42   40 %
    Microsoft YaHei                           Swiss                (2312)        15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                  15 x 42   40 %
    Microsoft Yi Baiti                        Script                              21 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU                                   Modern      Regular                        16 x 32   40 %
    MingLiU                                   Modern      Regular         (BIG5)        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular                        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular         (BIG5)        16 x 32   40 %
    Miriam Fixed                              Modern      Regular                           19 x 32   40 %
    Miriam                                    Swiss       Regular                           13 x 32   40 %
    Modern                                    Modern                     OEM/DOS                 19 x 37   40 %
    ModsFont                                  Special     Normal                         33 x 33   40 %
    Mongolian Baiti                           Script                              14 x 34   40 %
    MoolBoran                                 Swiss                               13 x 43   40 %
    MS Gothic                                 Modern      Regular                      16 x 32   40 %
    MS Gothic                                 Modern      Regular                       16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular                   16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular           16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                      16 x 32   40 %
    MS Mincho                                 Modern      Regular                       16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                   16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular           16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS PGothic                                Swiss       Regular                      13 x 32   40 %
    MS PGothic                                Swiss       Regular                       13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular                   13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular           13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                      13 x 32   40 %
    MS PMincho                                Roman       Regular                       13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                   13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular           13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS Sans Serif                             Swiss                                  5 x 13   40 %
    MS Serif                                  Roman                                  5 x 13   40 %
    MS UI Gothic                              Swiss       Regular                      13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                       13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                   13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular           13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MV Boli                                   Special                             18 x 52   40 %
    Narkisim                                  Swiss       Regular                           12 x 32   40 %
    NSimSun                                   Modern      Regular                        16 x 32   40 %
    NSimSun                                   Modern      Regular         (2312)        16 x 32   40 %
    Nyala                                     Special                           18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                18 x 33   40 %
    Palatino Linotype                         Roman                             14 x 43   40 %
    Palatino Linotype                         Roman                            14 x 43   40 %
    Palatino Linotype                         Roman                              14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                          14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                  14 x 43   40 %
    Plantagenet Cherokee                      Roman                               14 x 41   40 %
    PMingLiU                                  Roman       Regular                        16 x 32   40 %
    PMingLiU                                  Roman       Regular         (BIG5)        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    Raavi                                     Swiss       Regular                        13 x 53   40 %
    Rod                                       Modern      Regular                           19 x 31   40 %
    Roman                                     Roman                      OEM/DOS                 22 x 37   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                           16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                16 x 45   40 %
    Script                                    Script                     OEM/DOS                 16 x 36   40 %
    Segoe Print                               Special     Regular                      21 x 56   40 %
    Segoe Print                               Special     Regular                       21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular                   21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular           21 x 56   40 %
    Segoe Script                              Swiss                             22 x 51   40 %
    Segoe Script                              Swiss                              22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                          22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                  22 x 51   40 %
    Segoe UI Light                            Swiss       Regular                      17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                     17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                       17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                   17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular           17 x 43   30 %
    Segoe UI Semibold                         Swiss       Regular                      18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                     18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                       18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                   18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular           18 x 43   60 %
    Segoe UI Symbol                           Swiss                               23 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                             17 x 43   40 %
    Segoe UI                                  Swiss                            17 x 43   40 %
    Segoe UI                                  Swiss                              17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                          17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                  17 x 43   40 %
    Shonar Bangla                             Swiss       Regular                        16 x 41   40 %
    Shruti                                    Swiss       Regular                        14 x 54   40 %
    SimHei                                    Modern                              16 x 32   40 %
    SimHei                                    Modern               (2312)        16 x 32   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    SimSun                                    Special     Regular                        16 x 32   40 %
    SimSun                                    Special     Regular         (2312)        16 x 32   40 %
    SimSun-ExtB                               Modern                              16 x 32   40 %
    SimSun-ExtB                               Modern               (2312)        16 x 32   40 %
    Small Fonts                               Swiss                                   1 x 3   40 %
    Sylfaen                                   Roman                             13 x 42   40 %
    Sylfaen                                   Roman                              13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                          13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                  13 x 42   40 %
    Symbol                                    Roman                             19 x 39   40 %
    System                                    Swiss                                  7 x 16   70 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                             14 x 39   40 %
    Tahoma                                    Swiss                            14 x 39   40 %
    Tahoma                                    Swiss                              14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                                  14 x 39   40 %
    Tahoma                                    Swiss                          14 x 39   40 %
    Tahoma                                    Swiss                                14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                  14 x 39   40 %
    TeamViewer15                              Decorative  Medium                           22 x 32   50 %
    Terminal                                  Modern                     OEM/DOS                  8 x 12   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                             13 x 35   40 %
    Times New Roman                           Roman                            13 x 35   40 %
    Times New Roman                           Roman                              13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                                  13 x 35   40 %
    Times New Roman                           Roman                          13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                  13 x 35   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Trebuchet MS                              Swiss                             15 x 37   40 %
    Trebuchet MS                              Swiss                              15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                          15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                  15 x 37   40 %
    Tunga                                     Swiss       Regular                        18 x 53   40 %
    Univers Condensed                         Swiss                          12 x 39   70 %
    Univers Condensed                         Swiss                            12 x 39   70 %
    Univers Condensed                         Swiss                       12 x 39   70 %
    Univers Condensed                         Swiss                            12 x 39   70 %
    Univers Condensed                         Swiss               12 x 39   70 %
    Utsaah                                    Swiss       Regular                        13 x 36   40 %
    Vani                                      Swiss       Regular                        23 x 54   40 %
    Verdana                                   Swiss                             16 x 39   40 %
    Verdana                                   Swiss                            16 x 39   40 %
    Verdana                                   Swiss                              16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                          16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                  16 x 39   40 %
    Vijaya                                    Swiss       Regular                        19 x 32   40 %
    Vrinda                                    Swiss       Regular                        20 x 44   40 %
    Webdings                                  Roman                             31 x 32   40 %
    Wingdings                                 Special     Regular                      28 x 36   40 %


--------[  Windows ]-----------------------------------------------------------------------------------------------

    midi-out.0   0001 001B  Microsoft GS Wavetable Synth
    mixer.0      0001 0068   (Realtek High Definiti
    mixer.1      FFFF FFFF   (2- USB2.0 Camera)
    wave-in.0    FFFF FFFF   (2- USB2.0 Camera)
    wave-out.0   0001 0064   (Realtek High Definiti


--------[  PCI / PnP ]---------------------------------------------------------------------------------------------

    ATI Radeon HDMI @ AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller  PCI
    Realtek ALC887 @ ATI SB750 - High Definition Audio Controller                     PCI


--------[ HD Audio ]----------------------------------------------------------------------------------------------------

  [ AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller ]

     :
                                      AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        1 / 0 / 1
      ID                                      1002-AAB0
                               1787-AAB0
                                                  00
       ID                                     PCI\VEN_1002&DEV_AAB0&SUBSYS_AAB01787&REV_00

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/support
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates
                                     http://www.aida64.com/goto/?p=drvupdates

  [ ATI Radeon HDMI ]

     :
                                      ATI Radeon HDMI
        (Windows)                     AMD High Definition Audio Device
                                           Audio
                                                 HDAUDIO
      ID                                      1002-AA01
                               00AA-0100
                                                  1003
       ID                                     HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1003

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/support
                                     http://www.aida64.com/goto/?p=drvupdates

  [ ATI SB750 - High Definition Audio Controller ]

     :
                                      ATI SB750 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        0 / 20 / 2
      ID                                      1002-4383
                               1043-8445
                                                  00
       ID                                     PCI\VEN_1002&DEV_4383&SUBSYS_84451043&REV_00

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/support
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates
                                     http://www.aida64.com/goto/?p=drvupdates

  [ Realtek ALC887 ]

     :
                                      Realtek ALC887
        (Windows)                     Realtek High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10EC-0887
                               1043-8445
                                                  1003
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_10438445&REV_1003

     :
                                                   Realtek Semiconductor Corp.
                                     https://www.realtek.com/products
                                       https://www.realtek.com/downloads
                                     http://www.aida64.com/goto/?p=drvupdates


--------[ OpenAL ]------------------------------------------------------------------------------------------------------

     OpenAL:
                                           Creative Labs Inc.
      Renderer                                          
                                                  1.1
                                           Generic Software
      OpenAL DLL                                        6.14.0357.25
      Creative OpenAL DLL                               
      Wrapper DLL                                       2.2.0.7
                                0
      X-RAM                                             

     OpenAL:
      AL_EXT_EXPONENT_DISTANCE                          
      AL_EXT_LINEAR_DISTANCE                            
      AL_EXT_OFFSET                                     
      ALC_ENUMERATE_ALL_EXT                             
      ALC_ENUMERATION_EXT                               
      ALC_EXT_CAPTURE                                   
      ALC_EXT_EFX                                       
      EAX                                               
      EAX2.0                                            
      EAX3.0                                             
      EAX3.0EMULATED                                    
      EAX4.0                                             
      EAX4.0EMULATED                                    
      EAX5.0                                             
      EAX-RAM                                            


--------[   ]------------------------------------------------------------------------------------------------

  [ AAC ACM Codec ]

      ACM:
                                        AAC ACM Codec
      Copyright-                                   2011 by fccHandler
                                  GNU General Public License
                                         Advanced Audio Codec for Windows ACM
                                          1.09

  [ AC-3 ACM Codec ]

      ACM:
                                        AC-3 ACM Codec
      Copyright-                                   2005-2012 by fccHandler
                                  GNU General Public License
                                         Dolby Digital AC-3 codec for Windows ACM
                                          2.02

  [ ffdshow Audio Decoder ]

      ACM:
                                        ffdshow Audio Decoder
      Copyright-                                  2003-2005 Milan Cutka
                                  GNU GPL
                                         audio decoding and processing
                                          4.00

  [ Fraunhofer IIS MPEG Layer-3 Codec (decode only) ]

      ACM:
                                        Fraunhofer IIS MPEG Layer-3 Codec (decode only)
      Copyright-                                  Copyright  1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS
                                         decoder only version
                                          1.09

  [  ADPCM (Microsoft) ]

      ACM:
                                         ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             Microsoft ADPCM.
                                          4.00

  [  CCITT G.711 A-Law  u-Law (Microsoft) ]

      ACM:
                                         CCITT G.711 A-Law  u-Law (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                             CCITT G.711 A-Law / u-Law.
                                          4.00

  [  GSM 6.10 (Microsoft) ]

      ACM:
                                         GSM 6.10 (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                                 ETSI-GSM (European Telecommunications Standards Institute-Groupe Special Mobile)  6.10.
                                          4.00

  [  IMA ADPCM (Microsoft) ]

      ACM:
                                         IMA ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             IMA ADPCM.
                                          4.00

  [  PCM Microsoft ]

      ACM:
                                         PCM Microsoft
      Copyright-                                    , 1992-1996.
                                                PCM.
                                          5.00

  [   Indeo audio ]

      ACM:
                                          Indeo audio
      Copyright-                                   Intel Corporation, 1997
                                           Indeo audio
                                          2.05


--------[   ]------------------------------------------------------------------------------------------------

    C:\PROGRA~2\x264vfw\x264vfw.dll  38_2274bm_36885                     
    C:\Windows\system32\utv_vcm.dll                                      
    C:\Windows\SysWOW64\CamCodec.dll  1.5.0.0                             
    C:\Windows\SysWOW64\CFHD.dll  3.2.2.185                           
    C:\Windows\SysWOW64\GeoCodec.dll  8.4.0.0                             
    C:\Windows\SysWOW64\GeoCodecD.dll  8.4.0.0                             
    C:\Windows\SysWOW64\ir41_32.dll  R4.11.15.94                         
    C:\Windows\SysWOW64\ir50_32.dll  R.5.10.15.2.55                      
    C:\Windows\SysWOW64\mlc.dll                                      
    C:\Windows\SysWOW64\vmnc.dll  7.1.2 build-301548                  
    C:\Windows\SysWOW64\vp8vfw.dll  1.2.0.0                             
    CamCodec.dll               1.5.0.0                             CamStudio Lossless Codec
    CFHD.dll                   3.2.2.185                           CineForm HD CODEC
    ff_vfw.dll                 1.3.4530.0                          FFDShow Video Encoder
    GeoCodec.dll               8.4.0.0                             GeoVision MPEG4
    GeoCodecD.dll              8.4.0.0                             GeoVision MPEG4 Decoder
    iccvid.dll                 1.10.0.11                            Cinepak
    ir41_32.dll                R4.11.15.94                         Indeo Video v.4.1 codec
    ir50_32.dll                R.5.10.15.2.55                      Ligos Indeo XP v.5.2 codec
    iyuv_32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Intel Indeo(R) Video YUV 
    lagarith.dll               1.3.27                              Lagarith lossless codec [LAGS]
    mlc.dll                                                        MLC Lossless Codec [MLCY]
    msrle32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Microsoft RLE Compressor
    msvidc32.dll               6.1.7600.16385 (win7_rtm.090713-1255)    Microsoft Video 1
    msyuv.dll                  6.1.7601.17514 (win7sp1_rtm.101119-1850)  Microsoft UYVY Video Decompressor
    tsbyuv.dll                 6.1.7601.17514 (win7sp1_rtm.101119-1850)  Toshiba Video Codec
    vmnc.dll                   7.1.2 build-301548                  VMnc lossless codec [VMnc]
    vp8vfw.dll                 1.2.0.0                             VP8 Video Codec
    xvidvfw.dll                                                    Xvid MPEG-4 Video Codec


--------[ MCI ]---------------------------------------------------------------------------------------------------------

  [ AVIVideo ]

      MCI:
                                              AVIVideo
                                                       Windows
                                                 MCI Video  Windows
                                                     Digital Video Device
                                                 mciavi32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
                                         
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ CDAudio ]

      MCI:
                                              CDAudio
                                                 MCI   cdaudio
                                                 mcicda.dll
                                                  

  [ MPEGVideo ]

      MCI:
                                              MPEGVideo
                                                     DirectShow
                                                 MCI DirectShow
                                                     Digital Video Device
                                                 mciqtz32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
                                         
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ Sequencer ]

      MCI:
                                              Sequencer
                                                      MIDI
                                                 MCI   MIDI
                                                     Sequencer Device
                                                 mciseq.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ WaveAudio ]

      MCI:
                                              WaveAudio
                                                     Sound
                                                 MCI   
                                                     Waveform Audio Device
                                                 mciwave.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          


--------[ SAPI ]--------------------------------------------------------------------------------------------------------

     SAPI:
       SAPI4                                      -
       SAPI5                                      5.3.13120.0

     (SAPI5):
                                                     Microsoft Anna - English (United States)
                                                Microsoft Anna - English (United States)
                                               M1033DSK
                                              C:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk
                                                 
                                                     
                                                     ()
                                           Microsoft
                                                  2.0
       DLL                                          C:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\MSTTSEngine.dll  (x86)
      CLSID                                             {F51C7B23-6566-424C-94CF-2C4F83EE96FF}
      Frontend                                          {55DFB4F7-4175-4B3B-B247-D9B399ADB119}

      (SAPI5):
                                                     Microsoft Speech Recognizer 8.0 for Windows (English - UK)
                                                Microsoft Speech Recognizer 8.0 for Windows (English - UK)
      FE Config Data File                               C:\Windows\Speech\Engines\SR\en-GB\c2057dsk.fe
                                                     ()
                                          Discrete;Continuous
                                      ();  ();  ( );  ();  ( );  ();  ( );  ();  (  );  ();  ();  ();  (); 
                                           Microsoft
                                                  8.0
       DLL                                          C:\Windows\System32\Speech\Engines\SR\spsreng.dll  (x64)
      CLSID                                             {DAC9F469-0C67-4643-9258-87EC128C5941}
      RecoExtension                                     {4F4DB904-CA35-4A3A-90AF-C9D8BE7532AC}

      (SAPI5):
                                                     Microsoft Speech Recognizer 8.0 for Windows (English - US)
                                                Microsoft Speech Recognizer 8.0 for Windows (English - US)
      FE Config Data File                               C:\Windows\Speech\Engines\SR\en-US\c1033dsk.fe
                                                     (); 
                                          Discrete;Continuous
                                      ();  ();  (); 
                                           Microsoft
                                                  8.0
       DLL                                          C:\Windows\System32\Speech\Engines\SR\spsreng.dll  (x64)
      CLSID                                             {DAC9F469-0C67-4643-9258-87EC128C5941}
      RecoExtension                                     {4F4DB904-CA35-4A3A-90AF-C9D8BE7532AC}


--------[   Windows ]-------------------------------------------------------------------------------------

  [ WD5001AALS-00LWTA0 ATA Device ]

     :
                                        WD5001AALS-00LWTA0 ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
      INF Section                                       disk_install.NT

  [ AMD PCI IDE Controller ]

     :
                                        AMD PCI IDE Controller
                                            04.12.2012
                                          5.2.2.179
                                       Advanced Micro Devices
      INF-                                          oem4.inf
      INF Section                                       amdide_Inst_64

     :
                                                    FF00-FF0F

  [ AMD SATA Controller (IDE Mode) ]

     :
                                        AMD SATA Controller (IDE Mode)
                                            04.12.2012
                                          5.2.2.179
                                       Advanced Micro Devices
      INF-                                          oem4.inf
      INF Section                                       amdide_Inst_64

     :
      IRQ                                               22
                                                  FE9FFC00-FE9FFFFF
                                                    8000-800F
                                                    9000-9003
                                                    A000-A007
                                                    B000-B003
                                                    C000-C007

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst


--------[   ]--------------------------------------------------------------------------------------------

    C:                                               NTFS         149649       47004      102645    69 %  1AF8-B532
    D:                                               NTFS         326937      141395      185542    57 %  30F6-7C5C


--------[   ]--------------------------------------------------------------------------------------------

  [  #1 - WD5001AALS-00LWTA0 (465 ) C: D: ]

    #1 ()    NTFS                                                             1 MB      350 MB
    #2               NTFS             C:                                            351 MB   149650 MB
    #3               NTFS             D:                                         150001 MB   326938 MB


--------[ ATA ]---------------------------------------------------------------------------------------------------------

  [ WD5001AALS-00LWTA0 (WMES2T388104) ]

      ATA:
      ID                                          WD5001AALS-00LWTA0
                                           WMES2T388104
                                                  01.00A01
      World Wide Name                                   5-0014EE-261736EAF
                                           SATA-II
                                               : 969021, : 16,   : 63,   : 512
       LBA                                       976773168
       /             512  / 512 
                                                   32767 
                                           16
      .  PIO                                   PIO 4
      .  MWDMA                                 MWDMA 2
      .  UDMA                                  UDMA 6
        UDMA                               UDMA 6
                                476940 
       ATA                                      ATA8-ACS

      ATA:
      48-bit LBA                                        , 
      Automatic Acoustic Management (AAM)                
      Device Configuration Overlay (DCO)                , 
      DMA Setup Auto-Activate                           , 
      Free-Fall Control                                  
      General Purpose Logging (GPL)                     , 
      Hardware Feature Control                           
      Host Protected Area (HPA)                         , 
      HPA Security Extensions                           , 
      Hybrid Information Feature                         
      In-Order Data Delivery                             
      Native Command Queuing (NCQ)                      
      NCQ Autosense                                      
      NCQ Priority Information                          
      NCQ Queue Management Command                       
      NCQ Streaming                                      
      Phy Event Counters                                
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      Sense Data Reporting (SDR)                         
      Service Interrupt                                  
      SMART                                             , 
      SMART Error Logging                               , 
      SMART Self-Test                                   , 
      Software Settings Preservation (SSP)              , 
      Streaming                                         , 
      Tagged Command Queuing (TCQ)                       
                                               , 
      Write-Read-Verify                                  

     SSD:
      Data Set Management                                
      Deterministic Read After TRIM                      
       TRIM                                       

     :
       (APM)                             
      Automatic Partial to Slumber Transitions (APST)   
      Device Initiated Interface Power Management (DIPM) 
      Device Sleep (DEVSLP)                              
      Extended Power Conditions (EPC)                    
      Host Initiated Interface Power Management (HIPM)  
      IDLE IMMEDIATE With UNLOAD FEATURE                , 
      Link Power State Device Sleep                      
                                          , 
      Power-Up In Standby (PUIS)                        , 

     ATA:
      DEVICE RESET                                       
      DOWNLOAD MICROCODE                                , 
      FLUSH CACHE                                       , 
      FLUSH CACHE EXT                                   , 
      NOP                                               , 
      READ BUFFER                                       , 
      WRITE BUFFER                                      , 


--------[ SMART ]-------------------------------------------------------------------------------------------------------

  [ WD5001AALS-00LWTA0 (WMES2T388104) ]

    01  Raw Read Error Rate                  51   200  200          79  OK:  
    03  Spinup Time                          21   186  184        3700  OK:  
    04  Start/Stop Count                     0    100  100         273  OK:  
    05  Reallocated Sector Count             140  200  200           0  OK:  
    07  Seek Error Rate                      0    100  253           0  OK:  
    09  Power-On Time Count                  0    98   98         1770  OK:  
    0A  Spinup Retry Count                   0    100  100           0  OK:  
    0B  Calibration Retry Count              0    100  100           0  OK:  
    0C  Power Cycle Count                    0    100  100         236  OK:  
    C0  Power-Off Retract Count              0    200  200          67  OK:  
    C1  Load/Unload Cycle Count              0    200  200         205  OK:  
    C2  Temperature                          0    110  103          33  OK:  
    C4  Reallocation Event Count             0    200  200           0  OK:  
    C5  Current Pending Sector Count         0    200  200           1  OK:  
    C6  Offline Uncorrectable Sector Count   0    100  253           0  OK:  
    C7  Ultra ATA CRC Error Rate             0    200  200           0  OK:  
    C8  Write Error Rate                     0    100  253           0  OK:  


--------[  Windows ]------------------------------------------------------------------------------------------------

  [ Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20) ]

      :
                                          Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
                                           Gigabit Ethernet
                                         60-45-CB-A4-9E-18
                                                 
                                      100 Mbps
      MTU                                               1500 
      DHCP-                               06.06.2020 9:00:41
      DHCP-                               06.06.2020 11:00:41
                                            19260020 (18.4 )
                                          1969803 (1.9 )

      :
      IP /                                  192.168.0.103 / 255.255.255.0
                                                    192.168.0.1
      DHCP                                              192.168.0.1
      DNS                                               193.109.160.1
      DNS                                               93.89.215.1

      :
                                                   Qualcomm Technologies, Inc.
                                     https://www.qualcomm.com/solutions/networking
                                       https://www.qualcomm.com
                                     http://www.aida64.com/goto/?p=drvupdates

  [ TAP-Windows Adapter V9 ]

      :
                                          TAP-Windows Adapter V9
                                           Ethernet
                                         00-FF-A3-40-A4-B2
                                                  2
                                      100 Mbps
      MTU                                               1500 
                                            0
                                          0


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller                             PCI


--------[ IAM ]---------------------------------------------------------------------------------------------------------

  [ Microsoft Communities ]

      :
                                        Microsoft Communities
      ID                                   account{F9A0D560-D99B-4D27-A1DD-FE2F17DE7C9A}.oeaccount
                                         ( )
                                           Microsoft Windows Mail
                                                (IE  )
      NNTP-                                       msnews.microsoft.com

      :
        NNTP                                
        NNTP                     
        NNTP                        
         NNTP             
       NNTP                
       NNTP   HTML                         

  [ Active Directory ]

      :
                                        Active Directory
      ID                                   account{320544FD-FCA7-4C84-B7E3-3A84F1A81B6C}.oeaccount
                                        LDAP
                                           Microsoft Windows Mail
                                                (IE  )
      LDAP-                                       NULL:3268
       LDAP                                        NULL
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     

  [    VeriSign ]

      :
                                           VeriSign
      ID                                   account{B451940E-0D26-4288-A6D0-B065FBC97916}.oeaccount
                                        LDAP
                                           Microsoft Windows Mail
                                                (IE  )
      LDAP-                                       directory.verisign.com
      LDAP URL                                          http://www.verisign.com
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        https://www.yandex.ru/?win=439&clid=2341035-16
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                                       C:\Windows\system32\blank.htm
                               

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.0.1  20   192.168.0.103 (Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20))
                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                127.0.0.1  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
              192.168.0.0    255.255.255.0    192.168.0.103  276  192.168.0.103 (Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20))
            192.168.0.103  255.255.255.255    192.168.0.103  276  192.168.0.103 (Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20))
            192.168.0.255  255.255.255.255    192.168.0.103  276  192.168.0.103 (Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20))
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                224.0.0.0        240.0.0.0    192.168.0.103  276  192.168.0.103 (Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20))
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255    192.168.0.103  276  192.168.0.103 (Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20))


--------[   ]--------------------------------------------------------------------------------------------

    2020-06-02 18:33:24  Home@file:///D:/GTA%20San%20Andreas/SAMPFUNCS/sampfuncs-settings.ini
    2020-06-03 09:40:22  Home@file:///C:/Users/Home/Desktop/Новый%20текстовый%20документ.txt
    2020-06-03 10:52:17  Home@file:///C:/Users/Home/Desktop/футболки/mortal_kombat_PNG23.png
    2020-06-03 10:59:47  Home@file:///C:/Users/Home/Desktop/футболки/я/Brawl_Stars.png
    2020-06-03 19:16:33  Home@file:///C:/Windows/Logs/CBS/CBS.log
    2020-06-05 08:15:01  Home@file:///C:/Users/Home/Downloads/antimm_3.rar
    2020-06-05 16:17:44  Home@file:///C:/Users/Home/Desktop/Дистанционное%20обучение/Новый%20текстовый%20документ.txt
    2020-06-05 20:36:25  Home@res://C:\Windows\system32\mmcndmgr.dll/views.htm
    2020-06-06 08:25:44  Home@file:///D:/Counter-Strike%20GO/steam/games/d1159d1a4d0e18da4d74f85dbb4934d7a92ace2b.ico
    2020-06-06 09:03:23  Home@file:///C:/Users/Home/Desktop/Minidump.zip
    2020-06-06 09:04:20  Home@file:///C:/Users/Home/Desktop/Дистанционное%20обучение/Новый%20текстовый%20документ%20(2).txt
    2020-06-06 09:05:33  Home@file:///C:/Users/Home/Desktop/Minidump.rar


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.7601.17514   Final Retail                         70656  21.11.2010 6:24:00
    bdaplgin.ax                               6.01.7600.16385   Final Retail                         74240  14.07.2009 4:14:10
    d2d1.dll                                  6.02.9200.16765   Final Retail  Russian                     3419136  26.11.2013 11:16:52
    d3d10.dll                                 6.02.9200.16492   Final Retail  English                     1080832  12.03.2016 15:31:52
    d3d10_1.dll                               6.02.9200.16492   Final Retail  English                      161792  12.03.2016 15:31:52
    d3d10_1core.dll                           6.02.9200.16492   Final Retail  English                      249856  12.03.2016 15:31:52
    d3d10core.dll                             6.02.9200.16492   Final Retail  English                      220160  12.03.2016 15:31:52
    d3d10level9.dll                           6.02.9200.16492   Final Retail  English                      604160  12.03.2016 15:31:52
    d3d10warp.dll                             6.02.9200.17033   Final Retail  English                     1987584  30.07.2015 20:57:32
    d3d11.dll                                 6.02.9200.16570   Final Retail  English                     1505280  12.03.2016 15:31:02
    d3d8.dll                                  6.01.7600.16385   Final Retail                    1036800  14.07.2009 4:15:08
    d3d8thk.dll                               6.01.7600.16385   Final Retail                      11264  14.07.2009 4:15:08
    d3d9.dll                                  6.01.7601.17514   Final Retail                    1828352  21.11.2010 6:24:23
    d3dim.dll                                 6.01.7600.16385   Final Retail                     386048  14.07.2009 4:15:08
    d3dim700.dll                              6.01.7600.16385   Final Retail                     817664  14.07.2009 4:15:08
    d3dramp.dll                               6.01.7600.16385   Final Retail                     593920  14.07.2009 4:15:08
    d3dxof.dll                                6.01.7600.16385   Final Retail                      53760  14.07.2009 4:15:08
    ddraw.dll                                 6.01.7600.16385   Final Retail                        531968  14.07.2009 4:15:10
    ddrawex.dll                               6.01.7600.16385   Final Retail                      30208  14.07.2009 4:15:10
    devenum.dll                               6.06.7601.19091   Final Retail                         67584  09.12.2015 0:53:41
    dinput.dll                                6.01.7600.16385   Final Retail                        136704  14.07.2009 4:15:11
    dinput8.dll                               6.01.7600.16385   Final Retail                        145408  14.07.2009 4:15:11
    dmband.dll                                6.01.7600.16385   Final Retail                      30720  14.07.2009 4:15:12
    dmcompos.dll                              6.01.7600.16385   Final Retail                      63488  14.07.2009 4:15:12
    dmime.dll                                 6.01.7600.16385   Final Retail                     179712  14.07.2009 4:15:12
    dmloader.dll                              6.01.7600.16385   Final Retail                      38400  14.07.2009 4:15:12
    dmscript.dll                              6.01.7600.16385   Final Retail                      86016  14.07.2009 4:15:12
    dmstyle.dll                               6.01.7600.16385   Final Retail                     105984  14.07.2009 4:15:12
    dmsynth.dll                               6.01.7600.16385   Final Retail                     105472  14.07.2009 4:15:12
    dmusic.dll                                6.01.7600.16385   Final Retail                        101376  14.07.2009 4:15:12
    dplaysvr.exe                              6.01.7600.16385   Final Retail                         29184  14.07.2009 4:14:18
    dplayx.dll                                6.01.7600.16385   Final Retail                     213504  14.07.2009 4:15:12
    dpmodemx.dll                              6.01.7600.16385   Final Retail                         23040  14.07.2009 4:15:12
    dpnaddr.dll                               6.01.7601.17514   Final Retail                       2560  21.11.2010 6:23:53
    dpnathlp.dll                              6.01.7600.16385   Final Retail  English                       57344  14.07.2009 4:15:14
    dpnet.dll                                 6.01.7601.17989   Final Retail                        376832  02.11.2012 8:11:31
    dpnhpast.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnhupnp.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnlobby.dll                              6.01.7600.16385   Final Retail                       2560  14.07.2009 4:04:52
    dpnsvr.exe                                6.01.7600.16385   Final Retail                         33280  14.07.2009 4:14:18
    dpwsockx.dll                              6.01.7600.16385   Final Retail                         44032  14.07.2009 4:15:12
    dsdmo.dll                                 6.01.7600.16385   Final Retail                     173568  14.07.2009 4:15:13
    dsound.dll                                6.01.7600.16385   Final Retail                        453632  14.07.2009 4:15:13
    dswave.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:13
    dwrite.dll                                6.02.9200.17568   Final Retail  Russian                     1251328  10.11.2015 21:39:20
    dxdiagn.dll                               6.01.7601.17514   Final Retail                        210432  21.11.2010 6:24:22
    dxgi.dll                                  6.02.9200.16492   Final Retail  English                      293376  12.03.2016 15:31:52
    dxmasf.dll                                12.00.7601.19148  Final Retail                       4096  09.02.2016 12:13:14
    dxtmsft.dll                               11.00.9600.18231  Final Retail  English                      416256  08.02.2016 23:20:48
    dxtrans.dll                               11.00.9600.18231  Final Retail  English                      279040  08.02.2016 23:11:32
    dxva2.dll                                 6.01.7600.16385   Final Retail  English                       88064  14.07.2009 4:15:14
    encapi.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:14
    gcdef.dll                                 6.01.7600.16385   Final Retail                        120832  14.07.2009 4:15:22
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  14.07.2009 4:14:10
    ir41_32.ax                                4.51.0016.0003    Final Retail                        839680  14.07.2009 4:14:10
    ir41_qc.dll                               4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir41_qcx.dll                              4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir50_32.dll                               5.2562.0015.0055  Final Retail                        746496  14.07.2009 4:15:34
    ir50_qc.dll                               5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ir50_qcx.dll                              5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  14.07.2009 4:14:10
    joy.cpl                                   6.01.7600.16385   Final Retail                        138240  14.07.2009 4:14:09
    ksproxy.ax                                6.01.7601.19091   Final Retail                        193536  09.12.2015 0:53:08
    kstvtune.ax                               6.01.7601.17514   Final Retail                         84480  21.11.2010 6:25:10
    ksuser.dll                                6.01.7601.19091   Final Retail                          4608  09.12.2015 0:53:47
    kswdmcap.ax                               6.01.7601.17514   Final Retail                        107008  21.11.2010 6:24:15
    ksxbar.ax                                 6.01.7601.17514   Final Retail                         48640  21.11.2010 6:25:10
    mciqtz32.dll                              6.06.7601.17514   Final Retail                         36352  21.11.2010 6:24:00
    mfc40.dll                                 4.01.0000.6151    Beta Retail                         954752  21.11.2010 6:24:00
    mfc42.dll                                 6.06.8064.0000    Beta Retail                        1137664  11.03.2011 8:33:59
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  05.06.2020 18:51:46
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  05.06.2020 18:51:47
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  05.06.2020 18:51:47
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  05.06.2020 18:51:37
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  05.06.2020 18:51:41
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  05.06.2020 18:51:43
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  05.06.2020 18:51:43
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  05.06.2020 18:51:43
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  05.06.2020 18:51:43
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  05.06.2020 18:51:44
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  05.06.2020 18:51:44
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  05.06.2020 18:51:45
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  05.06.2020 18:51:48
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  05.06.2020 18:51:48
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  05.06.2020 18:51:48
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  05.06.2020 18:51:49
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  05.06.2020 18:51:49
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  05.06.2020 18:51:46
    mpeg2data.ax                              6.06.7601.17514   Final Retail                         72704  21.11.2010 6:25:10
    mpg2splt.ax                               6.06.7601.17528   Final Retail                     199680  23.12.2010 8:50:23
    msdmo.dll                                 6.06.7601.17514   Final Retail                      30720  21.11.2010 6:24:02
    msdvbnp.ax                                6.06.7601.17514   Final Retail                         59904  21.11.2010 6:25:10
    msvidctl.dll                              6.05.7601.17514   Final Retail                       2291712  21.11.2010 6:25:10
    msyuv.dll                                 6.01.7601.17514   Final Retail                      22528  21.11.2010 6:23:50
    pid.dll                                   6.01.7600.16385   Final Retail                      36352  14.07.2009 4:16:12
    psisdecd.dll                              6.06.7601.17669   Final Retail                        465408  17.08.2011 7:24:12
    psisrndr.ax                               6.06.7601.17669   Final Retail                         75776  17.08.2011 7:19:27
    qasf.dll                                  12.00.7601.19091  Final Retail                     206848  09.12.2015 0:53:54
    qcap.dll                                  6.06.7601.17514   Final Retail                        190976  21.11.2010 6:24:08
    qdv.dll                                   6.06.7601.17514   Final Retail                        283136  21.11.2010 6:24:09
    qdvd.dll                                  6.06.7601.19091   Final Retail                        519680  09.12.2015 0:53:54
    qedit.dll                                 6.06.7601.19091   Final Retail                        509952  09.12.2015 0:53:54
    qedwipes.dll                              6.06.7600.16385   Final Retail                     733184  14.07.2009 4:09:35
    quartz.dll                                6.06.7601.19091   Final Retail                       1329664  09.12.2015 0:53:54
    vbisurf.ax                                6.01.7601.17514   Final Retail                      33792  21.11.2010 6:25:10
    vfwwdm32.dll                              6.01.7601.17514   Final Retail                         56832  21.11.2010 6:24:09
    wsock32.dll                               6.01.7600.16385   Final Retail                         15360  14.07.2009 4:16:20


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       aticfx32.dll (8.17.10.1680)
                                      AMD Radeon R7 240 Series

     Direct3D:
                                16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x
                               1 x 1
                              16384 x 16384
                              5.0
        DirectX                      DirectX v11.0

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Compute Shader                                    
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      Directional Lights                                
      DirectX Texture Compression                       
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Double-Precision Floating-Point                   
      Driver Concurrent Creates                         
      Driver Command Lists                               
      Dynamic Textures                                  
      Edge Anti-Aliasing                                 
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Geometry Shader                                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Map On Default Buffers                             
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Lights                                      
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Runtime Shader Linking                             
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Spot Lights                                       
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Tiled Resources                                    
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                   
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      ATIC                                              
      AYUV                                              
      CMSL                                              
      DXT1                                              
      DXT2                                              
      DXT3                                              
      DXT4                                              
      DXT5                                              
      FLGL                                              
      GET4                                              
      GINF                                              
      INST                                              
      M2IA                                              
      MMDX                                              
      NULL                                              
      NV12                                              
      NV21                                              
      R2VB                                              
      RESZ                                              
      SHDT                                              
      SYV2                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (Realtek High Definition Audio) ]

     DirectSound:
                                       (Realtek High Definition Audio)
                                          {0.0.0.00000000}.{0f18e974-48ff-4748-bc42-7b52a857329d}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[  Windows ]------------------------------------------------------------------------------------------

  [  ]

    IDE ATA/ATAPI :
      AMD PCI IDE Controller                            5.2.2.179
      AMD SATA Controller (IDE Mode)                    5.2.2.179
      ATA Channel 0                                     6.1.7601.18231
      ATA Channel 0                                     6.1.7601.18231
      ATA Channel 1                                     6.1.7601.18231
      ATA Channel 1                                     6.1.7601.18231

    :
        ()                    6.1.7600.16385

    :
      AMD Radeon R7 240 Series                          26.20.15029.27016

     :
      WD5001AALS-00LWTA0 ATA Device                     6.1.7600.16385

      :
      amdkmdag                                          
      Ancillary Function Driver for Winsock             
      AODDriver4.3.0                                    
      Beep                                              
      CNG                                               
      FairplayKD                                        
      FinalWire AIDA64 Kernel Driver                    
      Hardware Policy Driver                            
      HTTP                                              
      HWiNFO Kernel Driver                              
      KSecDD                                            
      KSecPkg                                           
      LDDM Graphics Subsystem                           
      Link-Layer Topology Discovery Mapper I/O Driver   
      Link-Layer Topology Discovery Responder           
      Malwarebytes Anti-Exploit                         
      msisadrv                                          
      NDProxy                                           
      NETBT                                             
      NSI proxy service driver.                         
      Null                                              
      pciide                                            
      PEAUTH                                            
      Performance Counters for Windows Driver           
      RDP Encoder Mirror Driver                         
      RDPCDD                                            
      Reflector Display Driver used to gain access to graphics data
      Security Processor Loader Driver                  
      System Attribute Cache                            
      TCP/IP Registry Compatibility                     
      User Mode Driver Frameworks Platform Driver       
      VgaSave                                           
      WFP Lightweight Filter                            
      xhunter1                                          
            
                              
                               
       QWAVE                                     
         Windows           
        NetIO Legacy TDI                
        TCP/IP                          
         IPv6 ARP               
          Bitlocker        
        (CLFS)                               
        QoS                           
        NDIS                            
                        
                               

    ,    :
      AMD High Definition Audio Device                  7.12.0.7733
      Realtek High Definition Audio                     6.0.1.7179
      USB2.0 Camera                                     6.1.7601.18208

    :
       HID                                    6.1.7601.17514

    :
      ACPI x64-based PC                                 6.1.7600.16385

     USB:
       USB-                         6.1.7601.18328
       USB-                         6.1.7601.18328
       USB-                         6.1.7601.18328
       USB-                         6.1.7601.18328
       USB-                         6.1.7601.18328
       USB-                         6.1.7601.18328
       USB-                         6.1.7601.18328
       USB                           6.1.7601.18328
       USB                           6.1.7601.18328
       OpenHCD USB -           6.1.7601.18328
       OpenHCD USB -           6.1.7601.18328
       OpenHCD USB -           6.1.7601.18328
       OpenHCD USB -           6.1.7601.18328
       OpenHCD USB -           6.1.7601.18328
        PCI - USB - 6.1.7601.18328
        PCI - USB - 6.1.7601.18328

    :
        PnP                         6.1.7600.16385

        :
      HID-                               6.1.7600.16385

     (COM  LPT):
      Nuvoton Communications Port (COM1)                1.0.2011.1109

    :
      AMD Athlon(tm) II X3 450 Processor                6.1.7600.16385
      AMD Athlon(tm) II X3 450 Processor                6.1.7600.16385
      AMD Athlon(tm) II X3 450 Processor                6.1.7600.16385

     :
      Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20)2.1.0.21
      TAP-Windows Adapter V9                            9.0.0.21
      WAN Miniport (IKEv2)                              6.1.7601.17514
       Microsoft ISATAP #2                       6.1.7600.16385
       Microsoft ISATAP                          6.1.7600.16385
       WAN (IP)                                 6.1.7601.17514
       WAN (IPv6)                               6.1.7601.17514
       WAN (L2TP)                               6.1.7601.17514
       WAN (PPPoE)                              6.1.7601.17514
       WAN (PPTP)                               6.1.7601.17514
      - WAN (SSTP)                              6.1.7601.17514
       WAN ( )                    6.1.7601.17514

     :
      AMD Log Utility Driver                            0.0.0.1
      AMD SMBus                                         5.12.0.15
      ATK0110 ACPI UTILITY                              1043.6.0.0
      CMOS                                         6.1.7601.17514
      Microsoft ACPI-                 6.1.7601.17514
      Microsoft System Management BIOS           6.1.7601.17514
      Remote Desktop Device Redirector Bus              6.1.7600.16385
      UMBus                    6.1.7601.17514
      UMBus                                6.1.7601.17514
                               6.1.7601.17514
                                       6.1.7601.17514
                               6.1.7601.17514
                                          6.1.7601.17514
                      6.1.7601.17514
                            6.1.7601.17514
          ()6.1.7601.17514
                               6.1.7600.16385
         ACPI Microsoft Windows   6.1.7601.17514
        ACPI                               6.1.7601.17514
       High Definition Audio (Microsoft)      6.1.7601.17514
       High Definition Audio (Microsoft)      6.1.7601.17514
                         6.1.7601.17514
        PCI    - ATI6.1.7601.17514
                            6.1.7601.17514
         Plug and Play 6.1.7601.17514
                     6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                          6.1.7601.17514
                                         6.1.7601.17514
        PCI  - CPU                       6.1.7601.17514
        PCI  - CPU                       6.1.7601.17514
        PCI  - CPU                       6.1.7601.17514
        PCI  - CPU                       6.1.7601.17514
        PCI  - CPU                       6.1.7601.17514
        PCI  - CPU                       6.1.7601.17514
        PCI - ISA                        6.1.7601.17514
        PCI - PCI                        6.1.7601.17514
        PCI - PCI                        6.1.7601.17514
         ACPI          6.1.7601.17514
       PCI                                          6.1.7601.17514

        :
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385

      :
                                        6.1.7601.17514
                                        6.1.7601.17514
                                        6.1.7601.17514

     HID (Human Interface Devices):
      HID-               6.1.7600.16385
      HID-               6.1.7600.16385
      HID-                         6.1.7601.18199
      USB-                               6.1.7601.18199
      USB-                               6.1.7601.18199
      USB-                               6.1.7601.18199

      :
      USB2.0 Camera                                     6.1.7601.18208

  [ IDE ATA/ATAPI  / AMD PCI IDE Controller ]

     :
                                        AMD PCI IDE Controller
                                            04.12.2012
                                          5.2.2.179
                                       Advanced Micro Devices
      INF-                                          oem4.inf
      INF Section                                       amdide_Inst_64
       ID                                     PCI\VEN_1002&DEV_439C&SUBSYS_83891043&REV_00
                                     PCI- 0,  20,  1
      PCI-                                    ATI SB750 - IDE Controller

     :
                                                    FF00-FF0F

  [ IDE ATA/ATAPI  / AMD SATA Controller (IDE Mode) ]

     :
                                        AMD SATA Controller (IDE Mode)
                                            04.12.2012
                                          5.2.2.179
                                       Advanced Micro Devices
      INF-                                          oem4.inf
      INF Section                                       amdide_Inst_64
       ID                                     PCI\VEN_1002&DEV_4390&SUBSYS_83891043&REV_00
                                     PCI- 0,  17,  0
      PCI-                                    ATI SB750 - SATA Controller

     :
      IRQ                                               22
                                                  FE9FFC00-FE9FFFFF
                                                    8000-800F
                                                    9000-9003
                                                    A000-A007
                                                    B000-B003
                                                    C000-C007

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst
       ID                                     1002-439c
                                     Channel 0

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst
       ID                                     1002-4390
                                     Channel 0

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst
       ID                                     1002-439c
                                     Channel 1

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       atapi_Inst
       ID                                     1002-4390
                                     Channel 1

  [  /   () ]

     :
                                          ()
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          battery.inf
      INF Section                                       COMPBATT_Inst.NT
       ID                                     COMPOSITE_BATTERY

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  / AMD Radeon R7 240 Series ]

     :
                                        AMD Radeon R7 240 Series
                                            21.04.2020
                                          26.20.15029.27016
                                       Advanced Micro Devices, Inc.
      INF-                                          oem12.inf
      INF Section                                       ati2mtag_R501
       ID                                     PCI\VEN_1002&DEV_6617&SUBSYS_20001787&REV_C7
                                     PCI- 1,  0,  0
      PCI-                                    AMD Radeon R7 240 (Oland) Video Adapter

     :
      IRQ                                               65536
                                                  000A0000-000BFFFF
                                                  D0000000-DFFFFFFF
                                                  FEAC0000-FEAFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    D000-D0FF

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates

  [   / WD5001AALS-00LWTA0 ATA Device ]

     :
                                        WD5001AALS-00LWTA0 ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
      INF Section                                       disk_install.NT
       ID                                     IDE\DiskWD5001AALS-00LWTA0______________________01.00A01
                                     Channel 1, Target 0, Lun 0

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [    / amdkmdag ]

     :
                                        amdkmdag

  [    / Ancillary Function Driver for Winsock ]

     :
                                        Ancillary Function Driver for Winsock

  [    / AODDriver4.3.0 ]

     :
                                        AODDriver4.3.0

  [    / Beep ]

     :
                                        Beep

  [    / CNG ]

     :
                                        CNG

  [    / FairplayKD ]

     :
                                        FairplayKD

  [    / FinalWire AIDA64 Kernel Driver ]

     :
                                        FinalWire AIDA64 Kernel Driver

  [    / Hardware Policy Driver ]

     :
                                        Hardware Policy Driver

  [    / HTTP ]

     :
                                        HTTP

  [    / HWiNFO Kernel Driver ]

     :
                                        HWiNFO Kernel Driver

  [    / KSecDD ]

     :
                                        KSecDD

  [    / KSecPkg ]

     :
                                        KSecPkg

  [    / LDDM Graphics Subsystem ]

     :
                                        LDDM Graphics Subsystem

  [    / Link-Layer Topology Discovery Mapper I/O Driver ]

     :
                                        Link-Layer Topology Discovery Mapper I/O Driver

  [    / Link-Layer Topology Discovery Responder ]

     :
                                        Link-Layer Topology Discovery Responder

  [    / Malwarebytes Anti-Exploit ]

     :
                                        Malwarebytes Anti-Exploit

  [    / msisadrv ]

     :
                                        msisadrv

  [    / NDProxy ]

     :
                                        NDProxy

  [    / NETBT ]

     :
                                        NETBT

  [    / NSI proxy service driver. ]

     :
                                        NSI proxy service driver.

  [    / Null ]

     :
                                        Null

  [    / pciide ]

     :
                                        pciide

  [    / PEAUTH ]

     :
                                        PEAUTH

  [    / Performance Counters for Windows Driver ]

     :
                                        Performance Counters for Windows Driver

  [    / RDP Encoder Mirror Driver ]

     :
                                        RDP Encoder Mirror Driver

  [    / RDPCDD ]

     :
                                        RDPCDD

  [    / Reflector Display Driver used to gain access to graphics data ]

     :
                                        Reflector Display Driver used to gain access to graphics data

  [    / Security Processor Loader Driver ]

     :
                                        Security Processor Loader Driver

  [    / System Attribute Cache ]

     :
                                        System Attribute Cache

  [    / TCP/IP Registry Compatibility ]

     :
                                        TCP/IP Registry Compatibility

  [    / User Mode Driver Frameworks Platform Driver ]

     :
                                        User Mode Driver Frameworks Platform Driver

  [    / VgaSave ]

     :
                                        VgaSave

  [    / WFP Lightweight Filter ]

     :
                                        WFP Lightweight Filter

  [    / xhunter1 ]

     :
                                        xhunter1

  [    /        ]

     :
                                              

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /  QWAVE ]

     :
                                         QWAVE

  [    /    Windows ]

     :
                                           Windows

  [    /   NetIO Legacy TDI ]

     :
                                          NetIO Legacy TDI

  [    /   TCP/IP ]

     :
                                          TCP/IP

  [    /    IPv6 ARP ]

     :
                                           IPv6 ARP

  [    /     Bitlocker ]

     :
                                            Bitlocker

  [    /   (CLFS) ]

     :
                                          (CLFS)

  [    /   QoS ]

     :
                                          QoS

  [    /   NDIS ]

     :
                                          NDIS

  [    /      ]

     :
                                            

  [    /    ]

     :
                                          

  [ ,     / AMD High Definition Audio Device ]

     :
                                        AMD High Definition Audio Device
                                            10.07.2019
                                          7.12.0.7733
                                       Advanced Micro Devices
      INF-                                          oem10.inf
      INF Section                                       HDAudioInstall
       ID                                     HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1003
                                       High Definition Audio

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/support
                                     http://www.aida64.com/goto/?p=drvupdates

  [ ,     / Realtek High Definition Audio ]

     :
                                        Realtek High Definition Audio
                                            18.02.2014
                                          6.0.1.7179
                                       Realtek Semiconductor Corp.
      INF-                                          oem7.inf
      INF Section                                       IntcAzAudModel.NTAMD64
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_10438445&REV_1003
                                       High Definition Audio

     :
                                                   Realtek Semiconductor Corp.
                                     https://www.realtek.com/products
                                       https://www.realtek.com/downloads
                                     http://www.aida64.com/goto/?p=drvupdates

  [ ,     / USB2.0 Camera ]

     :
                                        USB2.0 Camera
                                            12.07.2013
                                          6.1.7601.18208
                                       Microsoft
      INF-                                          wdma_usb.inf
      INF Section                                       USBAudio
       ID                                     USB\VID_1871&PID_0142&REV_000<&MI_02
                                     0000.0012.0002.004.000.000.000.000.000

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  /  HID ]

     :
                                         HID
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          keyboard.inf
      INF Section                                       HID_Keyboard_Inst.NT
       ID                                     HID\VID_046D&PID_C31C&REV_6400&MI_00

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  / ACPI x64-based PC ]

     :
                                        ACPI x64-based PC
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hal.inf
      INF Section                                       ACPI_AMD64_HAL
       ID                                     acpiapic

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       ROOTHUB.Dev.NT
       ID                                     USB\ROOT_HUB&VID1002&PID4398&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       ROOTHUB.Dev.NT
       ID                                     USB\ROOT_HUB&VID1002&PID4397&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       ROOTHUB.Dev.NT
       ID                                     USB\ROOT_HUB&VID1002&PID4399&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       ROOTHUB.Dev.NT
       ID                                     USB\ROOT_HUB&VID1002&PID4398&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       ROOTHUB.Dev.NT
       ID                                     USB\ROOT_HUB&VID1002&PID4397&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       ROOTHUB.Dev.NT
       ID                                     USB\ROOT_HUB20&VID1002&PID4396&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       ROOTHUB.Dev.NT
       ID                                     USB\ROOT_HUB20&VID1002&PID4396&REV0000

  [  USB /  USB  ]

     :
                                         USB 
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usb.inf
      INF Section                                       Composite.Dev.NT
       ID                                     USB\VID_1871&PID_0142&REV_000<
                                     Port_#0004.Hub_#0003

  [  USB /  USB  ]

     :
                                         USB 
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usb.inf
      INF Section                                       Composite.Dev.NT
       ID                                     USB\VID_046D&PID_C31C&REV_6400
                                     Port_#0002.Hub_#0001

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       OHCI.Dev.NT
       ID                                     PCI\VEN_1002&DEV_4397&SUBSYS_83891043&REV_00
                                     PCI- 0,  19,  0
      PCI-                                    ATI SB750 - OHCI USB Controller

     :
      IRQ                                               18
                                                  FE9FC000-FE9FCFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       OHCI.Dev.NT
       ID                                     PCI\VEN_1002&DEV_4398&SUBSYS_83891043&REV_00
                                     PCI- 0,  18,  1
      PCI-                                    ATI SB750 - OHCI USB Controller

     :
      IRQ                                               16
                                                  FE9FD000-FE9FDFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       OHCI.Dev.NT
       ID                                     PCI\VEN_1002&DEV_4398&SUBSYS_83891043&REV_00
                                     PCI- 0,  19,  1
      PCI-                                    ATI SB750 - OHCI USB Controller

     :
      IRQ                                               18
                                                  FE9FB000-FE9FBFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       OHCI.Dev.NT
       ID                                     PCI\VEN_1002&DEV_4399&SUBSYS_83891043&REV_00
                                     PCI- 0,  20,  5
      PCI-                                    ATI SB750 - OHCI USB Controller

     :
      IRQ                                               18
                                                  FE9FA000-FE9FAFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       OHCI.Dev.NT
       ID                                     PCI\VEN_1002&DEV_4397&SUBSYS_83891043&REV_00
                                     PCI- 0,  18,  0
      PCI-                                    ATI SB750 - OHCI USB Controller

     :
      IRQ                                               16
                                                  FE9FE000-FE9FEFFF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       EHCI.Dev.NT
       ID                                     PCI\VEN_1002&DEV_4396&SUBSYS_83891043&REV_00
                                     PCI- 0,  18,  2
      PCI-                                    ATI SB750 - EHCI USB 2.0 Controller

     :
      IRQ                                               17
                                                  FE9FF800-FE9FF8FF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.1.7601.18328
                                       Microsoft
      INF-                                          usbport.inf
      INF Section                                       EHCI.Dev.NT
       ID                                     PCI\VEN_1002&DEV_4396&SUBSYS_83891043&REV_00
                                     PCI- 0,  19,  2
      PCI-                                    ATI SB750 - EHCI USB 2.0 Controller

     :
      IRQ                                               19
                                                  FE9FF400-FE9FF4FF

  [  /   PnP ]

     :
                                          PnP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          monitor.inf
      INF Section                                       PnPMonitor.Install
       ID                                     MONITOR\GSM4BF0

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [      / HID-  ]

     :
                                        HID- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msmouse.inf
      INF Section                                       HID_Mouse_Inst.NT
       ID                                     HID\VID_1BCF&PID_0005&REV_0090

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  (COM  LPT) / Nuvoton Communications Port (COM1) ]

     :
                                        Nuvoton Communications Port (COM1)
                                            09.11.2011
                                          1.0.2011.1109
                                       Nuvoton Technology Corporation
      INF-                                          oem5.inf
      INF Section                                       Serial_Inst.NT
       ID                                     ACPI\PNP0501
      PnP-                                    16550A-compatible UART Serial Port

     :
      IRQ                                               04
                                                    03F8-03FF

  [  / AMD Athlon(tm) II X3 450 Processor ]

     :
                                        AMD Athlon(tm) II X3 450 Processor
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
      INF Section                                       AmdPPM_Inst.NT
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_16_Model_5

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com/en/products/processors-desktop
                                     http://www.aida64.com/goto/?p=drvupdates

  [  / AMD Athlon(tm) II X3 450 Processor ]

     :
                                        AMD Athlon(tm) II X3 450 Processor
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
      INF Section                                       AmdPPM_Inst.NT
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_16_Model_5

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com/en/products/processors-desktop
                                     http://www.aida64.com/goto/?p=drvupdates

  [  / AMD Athlon(tm) II X3 450 Processor ]

     :
                                        AMD Athlon(tm) II X3 450 Processor
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
      INF Section                                       AmdPPM_Inst.NT
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_16_Model_5

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com/en/products/processors-desktop
                                     http://www.aida64.com/goto/?p=drvupdates

  [   / Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20) ]

     :
                                        Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
                                            16.07.2013
                                          2.1.0.21
                                       Qualcomm Atheros
      INF-                                          oem3.inf
      INF Section                                       L1F.MB.ndi
       ID                                     PCI\VEN_1969&DEV_10A1&SUBSYS_85871043&REV_10
                                     PCI- 2,  0,  0
      PCI-                                    Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller

     :
      IRQ                                               16
                                                  FEBC0000-FEBFFFFF
                                                    EC00-EC7F

      :
                                                   Qualcomm Technologies, Inc.
                                     https://www.qualcomm.com/solutions/networking
                                       https://www.qualcomm.com
                                     http://www.aida64.com/goto/?p=drvupdates

  [   / TAP-Windows Adapter V9 ]

     :
                                        TAP-Windows Adapter V9
                                            21.04.2016
                                          9.0.0.21
                                       TAP-Windows Provider V9
      INF-                                          oem13.inf
      INF Section                                       tap0901.ndi
       ID                                     tap0901

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   / WAN Miniport (IKEv2) ]

     :
                                        WAN Miniport (IKEv2)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netavpna.inf
      INF Section                                       Ndi-Mp-AgileVpn
       ID                                     ms_agilevpnminiport

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   /  Microsoft ISATAP #2 ]

     :
                                         Microsoft ISATAP #2
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
      INF Section                                       ISATAP.ndi
       ID                                     *ISATAP

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   /  Microsoft ISATAP ]

     :
                                         Microsoft ISATAP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
      INF Section                                       ISATAP.ndi
       ID                                     *ISATAP

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   /  WAN (IP) ]

     :
                                         WAN (IP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
      INF Section                                       Ndi-Mp-Ip
       ID                                     ms_ndiswanip

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   /  WAN (IPv6) ]

     :
                                         WAN (IPv6)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
      INF Section                                       Ndi-Mp-Ipv6
       ID                                     ms_ndiswanipv6

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   /  WAN (L2TP) ]

     :
                                         WAN (L2TP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
      INF Section                                       Ndi-Mp-L2tp
       ID                                     ms_l2tpminiport

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   /  WAN (PPPoE) ]

     :
                                         WAN (PPPoE)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
      INF Section                                       Ndi-Mp-Pppoe
       ID                                     ms_pppoeminiport

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   /  WAN (PPTP) ]

     :
                                         WAN (PPTP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
      INF Section                                       Ndi-Mp-Pptp
       ID                                     ms_pptpminiport

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   / - WAN (SSTP) ]

     :
                                        - WAN (SSTP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netsstpa.inf
      INF Section                                       Ndi-Mp-Sstp
       ID                                     ms_sstpminiport

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   /  WAN ( ) ]

     :
                                         WAN ( )
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
      INF Section                                       Ndi-Mp-Bh
       ID                                     ms_ndiswanbh

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [   / AMD Log Utility Driver ]

     :
                                        AMD Log Utility Driver
                                            12.12.2019
                                          0.0.0.1
                                       Advanced Micro Devices, Inc
      INF-                                          oem14.inf
      INF Section                                       AMD Log64
       ID                                     ROOT\AMDLOG

  [   / AMD SMBus ]

     :
                                        AMD SMBus
                                            16.03.2011
                                          5.12.0.15
                                       Advanced Micro Devices, Inc
      INF-                                          oem2.inf
      INF Section                                       AMDSMBus64
       ID                                     PCI\VEN_1002&DEV_4385&SUBSYS_83891043&REV_3C
                                     PCI- 0,  20,  0
      PCI-                                    ATI SB750 - SMBus Controller

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/support
       BIOS                                 http://www.aida64.com/goto/?p=biosupdates
                                     http://www.aida64.com/goto/?p=drvupdates

  [   / ATK0110 ACPI UTILITY ]

     :
                                        ATK0110 ACPI UTILITY
                                            16.07.2009
                                          1043.6.0.0
                                       ATK
      INF-                                          oem8.inf
      INF Section                                       DriverInstall
       ID                                     ACPI\ATK0110
      PnP-                                    Asus ATK-110 ACPI Utility

  [   / CMOS   ]

     :
                                        CMOS  
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_X
       ID                                     ACPI\PNP0B00
      PnP-                                    Real-Time Clock

     :
      IRQ                                               08
                                                    0070-0071

  [   / Microsoft ACPI-  ]

     :
                                        Microsoft ACPI- 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          acpi.inf
      INF Section                                       ACPI_Inst.NT
       ID                                     ACPI_HAL\PNP0C08
      PnP-                                    ACPI Driver/BIOS

     :
      IRQ                                               100
      IRQ                                               101
      IRQ                                               102
      IRQ                                               103
      IRQ                                               104
      IRQ                                               105
      IRQ                                               106
      IRQ                                               107
      IRQ                                               108
      IRQ                                               109
      IRQ                                               110
      IRQ                                               111
      IRQ                                               112
      IRQ                                               113
      IRQ                                               114
      IRQ                                               115
      IRQ                                               116
      IRQ                                               117
      IRQ                                               118
      IRQ                                               119
      IRQ                                               120
      IRQ                                               121
      IRQ                                               122
      IRQ                                               123
      IRQ                                               124
      IRQ                                               125
      IRQ                                               126
      IRQ                                               127
      IRQ                                               128
      IRQ                                               129
      IRQ                                               130
      IRQ                                               131
      IRQ                                               132
      IRQ                                               133
      IRQ                                               134
      IRQ                                               135
      IRQ                                               136
      IRQ                                               137
      IRQ                                               138
      IRQ                                               139
      IRQ                                               140
      IRQ                                               141
      IRQ                                               142
      IRQ                                               143
      IRQ                                               144
      IRQ                                               145
      IRQ                                               146
      IRQ                                               147
      IRQ                                               148
      IRQ                                               149
      IRQ                                               150
      IRQ                                               151
      IRQ                                               152
      IRQ                                               153
      IRQ                                               154
      IRQ                                               155
      IRQ                                               156
      IRQ                                               157
      IRQ                                               158
      IRQ                                               159
      IRQ                                               160
      IRQ                                               161
      IRQ                                               162
      IRQ                                               163
      IRQ                                               164
      IRQ                                               165
      IRQ                                               166
      IRQ                                               167
      IRQ                                               168
      IRQ                                               169
      IRQ                                               170
      IRQ                                               171
      IRQ                                               172
      IRQ                                               173
      IRQ                                               174
      IRQ                                               175
      IRQ                                               176
      IRQ                                               177
      IRQ                                               178
      IRQ                                               179
      IRQ                                               180
      IRQ                                               181
      IRQ                                               182
      IRQ                                               183
      IRQ                                               184
      IRQ                                               185
      IRQ                                               186
      IRQ                                               187
      IRQ                                               188
      IRQ                                               189
      IRQ                                               190
      IRQ                                               81
      IRQ                                               82
      IRQ                                               83
      IRQ                                               84
      IRQ                                               85
      IRQ                                               86
      IRQ                                               87
      IRQ                                               88
      IRQ                                               89
      IRQ                                               90
      IRQ                                               91
      IRQ                                               92
      IRQ                                               93
      IRQ                                               94
      IRQ                                               95
      IRQ                                               96
      IRQ                                               97
      IRQ                                               98
      IRQ                                               99

  [   / Microsoft System Management BIOS  ]

     :
                                        Microsoft System Management BIOS 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       MSSMBIOS_DRV
       ID                                     ROOT\mssmbios

  [   / Remote Desktop Device Redirector Bus ]

     :
                                        Remote Desktop Device Redirector Bus
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          rdpbus.inf
      INF Section                                       RDPBUS
       ID                                     ROOT\RDPBUS

  [   / UMBus    ]

     :
                                        UMBus   
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          umbus.inf
      INF Section                                       UmBusRoot_Device.NT
       ID                                     root\umbus

  [   / UMBus  ]

     :
                                        UMBus 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          umbus.inf
      INF Section                                       UmBus_Device.NT
       ID                                     UMB\UMBUS

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_X
       ID                                     ACPI\PNP0C04
      PnP-                                    Numeric Data Processor

     :
      IRQ                                               13
                                                    00F0-00FF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_X
       ID                                     ACPI\PNP0800
      PnP-                                    PC Speaker

     :
                                                    0061-0061

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_HPET
       ID                                     ACPI\PNP0103
      PnP-                                    High Precision Event Timer

     :
                                                  FED00000-FED003FF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       Volmgr
       ID                                     ROOT\VOLMGR

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       RDP_KBD
       ID                                     ROOT\RDP_KBD

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       RDP_MOU
       ID                                     ROOT\RDP_MOU

  [   /     () ]

     :
                                            ()
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       VDRVROOT
       ID                                     ROOT\vdrvroot

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          blbdrive.inf
      INF Section                                       blbdrive_device.NT
       ID                                     ROOT\BLBDRIVE

  [   /    ACPI Microsoft Windows ]

     :
                                           ACPI Microsoft Windows
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          acpi.inf
      INF Section                                       WMIMAP_Inst.NT
       ID                                     ACPI\PNP0C14
      PnP-                                    Microsoft Windows Management Interface for ACPI

  [   /   ACPI ]

     :
                                          ACPI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV
       ID                                     ACPI\PNP0C0C
      PnP-                                    Power Button

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            19.11.2010
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          hdaudbus.inf
      INF Section                                       HDAudio_Device.NT
       ID                                     PCI\VEN_1002&DEV_4383&SUBSYS_84451043&REV_00
                                     PCI- 0,  20,  2
      PCI-                                    ATI SB750 - High Definition Audio Controller

     :
      IRQ                                               16
                                                  FE9F4000-FE9F7FFF

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            19.11.2010
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          hdaudbus.inf
      INF Section                                       HDAudio_Device.NT
       ID                                     PCI\VEN_1002&DEV_AAB0&SUBSYS_AAB01787&REV_00
                                     PCI- 1,  0,  1
      PCI-                                    AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller

     :
      IRQ                                               19
                                                  FEA9C000-FEA9FFFF

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_X
       ID                                     ACPI\PNP0200
      PnP-                                    DMA Controller

     :
      DMA                                               04
                                                    0000-000F
                                                    0081-0083
                                                    0087-0087
                                                    0089-008B
                                                    008F-008F
                                                    00C0-00DF

  [   /   PCI    - ATI ]

     :
                                          PCI    - ATI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       PCI_DRV
       ID                                     PCI\VEN_1002&DEV_4384&SUBSYS_00000000&REV_00
                                     PCI- 0,  20,  4
      PCI-                                    ATI SB750 - PCI-PCI Bridge

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          compositebus.inf
      INF Section                                       CompositeBus_Device.NT
       ID                                     ROOT\CompositeBus

  [   /    Plug and Play ]

     :
                                           Plug and Play
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       SWENUM
       ID                                     root\swenum

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_PIC
       ID                                     ACPI\PNP0000
      PnP-                                    Programmable Interrupt Controller

     :
                                                    0020-0021
                                                    00A0-00A1

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_MBRES
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  E0000000-EFFFFFFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_MBRES
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  FEC00000-FEC00FFF
                                                  FEE00000-FEE00FFF
                                                    0060-0060
                                                    0064-0064

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_MBRES
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  CFF00000-CFFFFFFF
                                                  FEC10000-FEC1001F
                                                  FED40000-FED44FFF
                                                  FFB80000-FFBFFFFF
                                                    0010-001F
                                                    0022-003F
                                                    0060-0060
                                                    0062-0063
                                                    0064-0064
                                                    0065-006F
                                                    0072-007F
                                                    0080-0080
                                                    0084-0086
                                                    0088-0088
                                                    008C-008E
                                                    0090-009F
                                                    00A2-00BF
                                                    00B1-00B1
                                                    00E0-00EF
                                                    040B-040B
                                                    04D0-04D1
                                                    04D6-04D6
                                                    0800-089F
                                                    0900-090F
                                                    0910-091F
                                                    0B00-0B0F
                                                    0B00-0B3F
                                                    0B20-0B3F
                                                    0C00-0C01
                                                    0C14-0C14
                                                    0C50-0C51
                                                    0C52-0C52
                                                    0C6C-0C6C
                                                    0C6F-0C6F
                                                    0CD0-0CD1
                                                    0CD2-0CD3
                                                    0CD4-0CD5
                                                    0CD6-0CD7
                                                    0CD8-0CDF
                                                    FE00-FEFE

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_MBRES
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_MBRES
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                    0230-023F
                                                    0290-029F
                                                    0300-030F
                                                    0A30-0A3F

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_MBRES
       ID                                     ACPI\PNP0C01
      PnP-                                    System Board Extension

     :
                                                  00000000-0009FFFF
                                                  000C0000-000CFFFF
                                                  000E0000-000FFFFF
                                                  00100000-CFEFFFFF
                                                  FEC00000-FFFFFFFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV_X
       ID                                     ACPI\PNP0100
      PnP-                                    System Timer

     :
      IRQ                                               00
                                                    0040-0043

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV
       ID                                     PCI\VEN_1022&DEV_1200&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  0
      PCI-                                    AMD K10 - HyperTransport Technology Configuration

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV
       ID                                     PCI\VEN_1022&DEV_1201&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  1
      PCI-                                    AMD K10 - Address Map

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV
       ID                                     PCI\VEN_1022&DEV_1202&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  2
      PCI-                                    AMD K10 - DRAM Controller

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV
       ID                                     PCI\VEN_1022&DEV_1203&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  3
      PCI-                                    AMD K10 - Miscellaneous Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV
       ID                                     PCI\VEN_1022&DEV_1204&SUBSYS_00000000&REV_00
                                     PCI- 0,  24,  4
      PCI-                                    AMD K10 - Link Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV
       ID                                     PCI\VEN_1022&DEV_9600&SUBSYS_83881043&REV_00
                                     PCI- 0,  0,  0
      PCI-                                    AMD RS780/RS880 Chipset - Host Bridge

  [   /   PCI - ISA ]

     :
                                          PCI - ISA
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       MSISADRV
       ID                                     PCI\VEN_1002&DEV_439D&SUBSYS_83891043&REV_00
                                     PCI- 0,  20,  3
      PCI-                                    ATI SB750 - PCI-LPC Bridge

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       PCI_DRV
       ID                                     PCI\VEN_1022&DEV_9603&SUBSYS_83881043&REV_00
                                     PCI- 0,  2,  0
      PCI-                                    AMD RS780/RS880 Chipset - PCI Express Graphics Port 0

     :
      IRQ                                               18
                                                  000A0000-000BFFFF
                                                  D0000000-DFFFFFFF
                                                  FEA00000-FEAFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    D000-DFFF

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       PCI_DRV
       ID                                     PCI\VEN_1022&DEV_9604&SUBSYS_83881043&REV_00
                                     PCI- 0,  4,  0
      PCI-                                    AMD RS780/RS880 Chipset - PCI Express Port 0

     :
      IRQ                                               16
                                                  FEB00000-FEBFFFFF
                                                    E000-EFFF

  [   /    ACPI ]

     :
                                           ACPI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       NO_DRV
       ID                                     ACPI\FixedButton

  [   /  PCI ]

     :
                                         PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
      INF Section                                       PCI_DRV_ROOT
       ID                                     ACPI\PNP0A03
      PnP-                                    PCI Bus

     :
                                                  000A0000-000BFFFF
                                                  000D0000-000DFFFF
                                                  CFF00000-DFFFFFFF
                                                  F0000000-FEBFFFFF
                                                    0000-0CF7
                                                    0D00-FFFF

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
      INF Section                                       volume_snapshot_install.NTAMD64
       ID                                     STORAGE\VolumeSnapshot

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          volume.inf
      INF Section                                       volume_install.NTAMD64
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          volume.inf
      INF Section                                       volume_install.NTAMD64
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          volume.inf
      INF Section                                       volume_install.NTAMD64
       ID                                     STORAGE\Volume

  [  HID (Human Interface Devices) / HID-   ]

     :
                                        HID-  
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hidserv.inf
      INF Section                                       HIDSystemConsumerDevice
       ID                                     HID\VID_046D&PID_C31C&REV_6400&MI_01&Col01

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  HID (Human Interface Devices) / HID-   ]

     :
                                        HID-  
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hidserv.inf
      INF Section                                       HIDSystemConsumerDevice
       ID                                     HID\VID_046D&PID_C31C&REV_6400&MI_01&Col03

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  HID (Human Interface Devices) / HID-  ]

     :
                                        HID- 
                                            21.06.2006
                                          6.1.7601.18199
                                       Microsoft
      INF-                                          input.inf
      INF Section                                       HID_Raw_Inst.NT
       ID                                     HID\VID_046D&PID_C31C&REV_6400&MI_01&Col02

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  HID (Human Interface Devices) / USB-  ]

     :
                                        USB- 
                                            21.06.2006
                                          6.1.7601.18199
                                       Microsoft
      INF-                                          input.inf
      INF Section                                       HID_Inst.NT
       ID                                     USB\VID_1BCF&PID_0005&REV_0090
                                     Port_#0003.Hub_#0001

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  HID (Human Interface Devices) / USB-  ]

     :
                                        USB- 
                                            21.06.2006
                                          6.1.7601.18199
                                       Microsoft
      INF-                                          input.inf
      INF Section                                       HID_Inst.NT
       ID                                     USB\VID_046D&PID_C31C&REV_6400&MI_00
                                     0000.0012.0000.002.000.000.000.000.000

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [  HID (Human Interface Devices) / USB-  ]

     :
                                        USB- 
                                            21.06.2006
                                          6.1.7601.18199
                                       Microsoft
      INF-                                          input.inf
      INF Section                                       HID_Inst.NT
       ID                                     USB\VID_046D&PID_C31C&REV_6400&MI_01
                                     0000.0012.0000.002.000.000.000.000.000

     :
                                     http://www.aida64.com/goto/?p=drvupdates

  [    / USB2.0 Camera ]

     :
                                        USB2.0 Camera
                                            21.06.2006
                                          6.1.7601.18208
                                       Microsoft
      INF-                                          usbvideo.inf
      INF Section                                       USBVideo.NT
       ID                                     USB\VID_1871&PID_0142&REV_000<&MI_00
                                     0000.0012.0002.004.000.000.000.000.000

     :
                                     http://www.aida64.com/goto/?p=drvupdates


--------[   ]---------------------------------------------------------------------------------------

     PCI:
       1,  0,  1                   AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller
       0,  24,  1                  AMD K10 - Address Map
       0,  24,  2                  AMD K10 - DRAM Controller
       0,  24,  0                  AMD K10 - HyperTransport Technology Configuration
       0,  24,  4                  AMD K10 - Link Control
       0,  24,  3                  AMD K10 - Miscellaneous Control
       1,  0,  0                   AMD Radeon R7 240 (Oland) Video Adapter
       0,  0,  0                   AMD RS780/RS880 Chipset - Host Bridge
       0,  2,  0                   AMD RS780/RS880 Chipset - PCI Express Graphics Port 0
       0,  4,  0                   AMD RS780/RS880 Chipset - PCI Express Port 0
       2,  0,  0                   Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller
       0,  18,  2                  ATI SB750 - EHCI USB 2.0 Controller
       0,  19,  2                  ATI SB750 - EHCI USB 2.0 Controller
       0,  20,  2                  ATI SB750 - High Definition Audio Controller
       0,  20,  1                  ATI SB750 - IDE Controller
       0,  18,  0                  ATI SB750 - OHCI USB Controller
       0,  18,  1                  ATI SB750 - OHCI USB Controller
       0,  19,  0                  ATI SB750 - OHCI USB Controller
       0,  19,  1                  ATI SB750 - OHCI USB Controller
       0,  20,  5                  ATI SB750 - OHCI USB Controller
       0,  20,  3                  ATI SB750 - PCI-LPC Bridge
       0,  20,  4                  ATI SB750 - PCI-PCI Bridge
       0,  17,  0                  ATI SB750 - SATA Controller
       0,  20,  0                  ATI SB750 - SMBus Controller

     PnP:
      PNP0501                                           16550A-compatible UART Serial Port
      PNP0C08                                           ACPI Driver/BIOS
      AUTHENTICAMD_-_AMD64_FAMILY_16_MODEL_5_-_AMD_ATHLON(TM)_II_X3_450_PROCESSORAMD Athlon(tm) II X3 450 Processor
      AUTHENTICAMD_-_AMD64_FAMILY_16_MODEL_5_-_AMD_ATHLON(TM)_II_X3_450_PROCESSORAMD Athlon(tm) II X3 450 Processor
      AUTHENTICAMD_-_AMD64_FAMILY_16_MODEL_5_-_AMD_ATHLON(TM)_II_X3_450_PROCESSORAMD Athlon(tm) II X3 450 Processor
      ATK0110                                           Asus ATK-110 ACPI Utility
      PNP0200                                           DMA Controller
      PNP0103                                           High Precision Event Timer
      PNP0C14                                           Microsoft Windows Management Interface for ACPI
      PNP0C04                                           Numeric Data Processor
      PNP0800                                           PC Speaker
      PNP0A03                                           PCI Bus
      PNP0C0C                                           Power Button
      PNP0000                                           Programmable Interrupt Controller
      PNP0B00                                           Real-Time Clock
      PNP0C01                                           System Board Extension
      PNP0100                                           System Timer
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      ISATAP                                             Microsoft ISATAP #2
      ISATAP                                             Microsoft ISATAP
      FIXEDBUTTON                                          ACPI

     USB:
      1871 0142                                         USB2.0 Camera
      1871 0142                                         USB2.0 Camera
      046D C31C                                         USB- 
      046D C31C                                         USB- 
      1BCF 0005                                         USB- 
      046D C31C                                          USB 
      1871 0142                                          USB 

    :
      COM1                                              Nuvoton Communications Port (COM1)


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller ]

     :
                                      AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller
                                                 PCI Express 2.0 x8
       /  /                        1 / 0 / 1
      ID                                      1002-AAB0
                               1787-AAB0
                                         0403 (High Definition Audio)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K10 - Address Map ]

     :
                                      AMD K10 - Address Map
                                                 PCI
       /  /                        0 / 24 / 1
      ID                                      1022-1201
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K10 - DRAM Controller ]

     :
                                      AMD K10 - DRAM Controller
                                                 PCI
       /  /                        0 / 24 / 2
      ID                                      1022-1202
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K10 - HyperTransport Technology Configuration ]

     :
                                      AMD K10 - HyperTransport Technology Configuration
                                                 PCI
       /  /                        0 / 24 / 0
      ID                                      1022-1200
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

    HyperTransport LDT0:
       HyperTransport                             3.00
                                                 
                                             
      .  /                    16  / 16 
        /          16  / 16 
                                2000 
                                     2000 
       /                     0 / 0
      Isochronous Flow Control Mode                     , 
      CRC Error Detected                                
      CRC Test Mode                                      
      Extended CTL Required                             
      Extended Register Set                              
      HyperTransport Stop Mode                          
      Link Failure Detected                             

  [ AMD K10 - Link Control ]

     :
                                      AMD K10 - Link Control
                                                 PCI
       /  /                        0 / 24 / 4
      ID                                      1022-1204
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K10 - Miscellaneous Control ]

     :
                                      AMD K10 - Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 3
      ID                                      1022-1203
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD Radeon R7 240 (Oland) Video Adapter ]

     :
                                      AMD Radeon R7 240 (Oland) Video Adapter
                                                 PCI Express 2.0 x8
       /  /                        1 / 0 / 0
      ID                                      1002-6617
                               1787-2000
                                         0300 (VGA Display Controller)
                                                  C7
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

     :
                                                   Advanced Micro Devices, Inc.
                                     https://www.amd.com
                                       https://www.amd.com/en/support
                                     http://www.aida64.com/goto/?p=drvupdates

  [ AMD RS780/RS880 Chipset - Host Bridge ]

     :
                                      AMD RS780/RS880 Chipset - Host Bridge
                                                 PCI
       /  /                        0 / 0 / 0
      ID                                      1022-9600
                               1043-8388
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ AMD RS780/RS880 Chipset - PCI Express Graphics Port 0 ]

     :
                                      AMD RS780/RS880 Chipset - PCI Express Graphics Port 0
                                                 PCI
       /  /                        0 / 2 / 0
      ID                                      1022-9603
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD RS780/RS880 Chipset - PCI Express Port 0 ]

     :
                                      AMD RS780/RS880 Chipset - PCI Express Port 0
                                                 PCI
       /  /                        0 / 4 / 0
      ID                                      1022-9604
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller ]

     :
                                      Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller
                                                 PCI Express 1.0 x1
       /  /                        2 / 0 / 0
      ID                                      1969-10A1
                               1043-8587
                                         0200 (Ethernet Controller)
                                                  10
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

      :
                                                   Qualcomm Technologies, Inc.
                                     https://www.qualcomm.com/solutions/networking
                                       https://www.qualcomm.com
                                     http://www.aida64.com/goto/?p=drvupdates

  [ ATI SB750 - EHCI USB 2.0 Controller ]

     :
                                      ATI SB750 - EHCI USB 2.0 Controller
                                                 PCI
       /  /                        0 / 18 / 2
      ID                                      1002-4396
                               1043-8389
                                         0C03 (USB2 EHCI Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - EHCI USB 2.0 Controller ]

     :
                                      ATI SB750 - EHCI USB 2.0 Controller
                                                 PCI
       /  /                        0 / 19 / 2
      ID                                      1002-4396
                               1043-8389
                                         0C03 (USB2 EHCI Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - High Definition Audio Controller ]

     :
                                      ATI SB750 - High Definition Audio Controller
                                                 PCI
       /  /                        0 / 20 / 2
      ID                                      1002-4383
                               1043-8445
                                         0403 (High Definition Audio)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ ATI SB750 - IDE Controller ]

     :
                                      ATI SB750 - IDE Controller
                                                 PCI
       /  /                        0 / 20 / 1
      ID                                      1002-439C
                               1043-8389
                                         0101 (IDE Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - OHCI USB Controller ]

     :
                                      ATI SB750 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 18 / 0
      ID                                      1002-4397
                               1043-8389
                                         0C03 (USB1 OHCI Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - OHCI USB Controller ]

     :
                                      ATI SB750 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 18 / 1
      ID                                      1002-4398
                               1043-8389
                                         0C03 (USB1 OHCI Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - OHCI USB Controller ]

     :
                                      ATI SB750 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 19 / 0
      ID                                      1002-4397
                               1043-8389
                                         0C03 (USB1 OHCI Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - OHCI USB Controller ]

     :
                                      ATI SB750 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 19 / 1
      ID                                      1002-4398
                               1043-8389
                                         0C03 (USB1 OHCI Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - OHCI USB Controller ]

     :
                                      ATI SB750 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 20 / 5
      ID                                      1002-4399
                               1043-8389
                                         0C03 (USB1 OHCI Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - PCI-LPC Bridge ]

     :
                                      ATI SB750 - PCI-LPC Bridge
                                                 PCI
       /  /                        0 / 20 / 3
      ID                                      1002-439D
                               1043-8389
                                         0601 (PCI/ISA Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - PCI-PCI Bridge ]

     :
                                      ATI SB750 - PCI-PCI Bridge
                                                 PCI
       /  /                        0 / 20 / 4
      ID                                      1002-4384
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - SATA Controller ]

     :
                                      ATI SB750 - SATA Controller
                                                 PCI
       /  /                        0 / 17 / 0
      ID                                      1002-4390
                               1043-8389
                                         0101 (IDE Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB750 - SMBus Controller ]

     :
                                      ATI SB750 - SMBus Controller
                                                 PCI
       /  /                        0 / 20 / 0
      ID                                      1002-4385
                               1043-8389
                                         0C05 (SMBus Controller)
                                                  3C
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     


--------[  USB ]----------------------------------------------------------------------------------------------

  [  USB  (USB2.0 Camera) ]

     :
                                       USB 
      ID                                      1871-0142
                                         EF / 02 (Interface Association Descriptor)
                                      01
                                                  000Ch
                                           AVEO Technology Corp.
                                                 USB2.0 Camera
        USB                         2.00
                                         High  (USB 2.0)

  [  USB  (USB Keyboard) ]

     :
                                       USB 
      ID                                      046D-C31C
                                         03 / 01 (Human Interface Device)
                                      01
                                                  6400h
                                           Logitech
                                                 USB Keyboard
        USB                         1.10
                                         Low  (USB 1.1)

  [ USB-  (USB Optical Mouse) ]

     :
                                      USB- 
      ID                                      1BCF-0005
                                         03 / 01 (Human Interface Device)
                                      02
                                                  0090h
                                                 USB Optical Mouse
        USB                         2.00
                                         Low  (USB 1.1)


--------[   ]-------------------------------------------------------------------------------------------

    DMA 04                                   
    IRQ 00                                
    IRQ 04                               Nuvoton Communications Port (COM1)
    IRQ 08                               CMOS  
    IRQ 100                              Microsoft ACPI- 
    IRQ 101                              Microsoft ACPI- 
    IRQ 102                              Microsoft ACPI- 
    IRQ 103                              Microsoft ACPI- 
    IRQ 104                              Microsoft ACPI- 
    IRQ 105                              Microsoft ACPI- 
    IRQ 106                              Microsoft ACPI- 
    IRQ 107                              Microsoft ACPI- 
    IRQ 108                              Microsoft ACPI- 
    IRQ 109                              Microsoft ACPI- 
    IRQ 110                              Microsoft ACPI- 
    IRQ 111                              Microsoft ACPI- 
    IRQ 112                              Microsoft ACPI- 
    IRQ 113                              Microsoft ACPI- 
    IRQ 114                              Microsoft ACPI- 
    IRQ 115                              Microsoft ACPI- 
    IRQ 116                              Microsoft ACPI- 
    IRQ 117                              Microsoft ACPI- 
    IRQ 118                              Microsoft ACPI- 
    IRQ 119                              Microsoft ACPI- 
    IRQ 120                              Microsoft ACPI- 
    IRQ 121                              Microsoft ACPI- 
    IRQ 122                              Microsoft ACPI- 
    IRQ 123                              Microsoft ACPI- 
    IRQ 124                              Microsoft ACPI- 
    IRQ 125                              Microsoft ACPI- 
    IRQ 126                              Microsoft ACPI- 
    IRQ 127                              Microsoft ACPI- 
    IRQ 128                              Microsoft ACPI- 
    IRQ 129                              Microsoft ACPI- 
    IRQ 13                                
    IRQ 130                              Microsoft ACPI- 
    IRQ 131                              Microsoft ACPI- 
    IRQ 132                              Microsoft ACPI- 
    IRQ 133                              Microsoft ACPI- 
    IRQ 134                              Microsoft ACPI- 
    IRQ 135                              Microsoft ACPI- 
    IRQ 136                              Microsoft ACPI- 
    IRQ 137                              Microsoft ACPI- 
    IRQ 138                              Microsoft ACPI- 
    IRQ 139                              Microsoft ACPI- 
    IRQ 14                               ATA Channel 0
    IRQ 140                              Microsoft ACPI- 
    IRQ 141                              Microsoft ACPI- 
    IRQ 142                              Microsoft ACPI- 
    IRQ 143                              Microsoft ACPI- 
    IRQ 144                              Microsoft ACPI- 
    IRQ 145                              Microsoft ACPI- 
    IRQ 146                              Microsoft ACPI- 
    IRQ 147                              Microsoft ACPI- 
    IRQ 148                              Microsoft ACPI- 
    IRQ 149                              Microsoft ACPI- 
    IRQ 15                               ATA Channel 1
    IRQ 150                              Microsoft ACPI- 
    IRQ 151                              Microsoft ACPI- 
    IRQ 152                              Microsoft ACPI- 
    IRQ 153                              Microsoft ACPI- 
    IRQ 154                              Microsoft ACPI- 
    IRQ 155                              Microsoft ACPI- 
    IRQ 156                              Microsoft ACPI- 
    IRQ 157                              Microsoft ACPI- 
    IRQ 158                              Microsoft ACPI- 
    IRQ 159                              Microsoft ACPI- 
    IRQ 16                                         OpenHCD USB -
    IRQ 16                                         OpenHCD USB -
    IRQ 16                                        Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
    IRQ 16                                         High Definition Audio (Microsoft)
    IRQ 16                                          PCI - PCI
    IRQ 160                              Microsoft ACPI- 
    IRQ 161                              Microsoft ACPI- 
    IRQ 162                              Microsoft ACPI- 
    IRQ 163                              Microsoft ACPI- 
    IRQ 164                              Microsoft ACPI- 
    IRQ 165                              Microsoft ACPI- 
    IRQ 166                              Microsoft ACPI- 
    IRQ 167                              Microsoft ACPI- 
    IRQ 168                              Microsoft ACPI- 
    IRQ 169                              Microsoft ACPI- 
    IRQ 17                                          PCI - USB -
    IRQ 170                              Microsoft ACPI- 
    IRQ 171                              Microsoft ACPI- 
    IRQ 172                              Microsoft ACPI- 
    IRQ 173                              Microsoft ACPI- 
    IRQ 174                              Microsoft ACPI- 
    IRQ 175                              Microsoft ACPI- 
    IRQ 176                              Microsoft ACPI- 
    IRQ 177                              Microsoft ACPI- 
    IRQ 178                              Microsoft ACPI- 
    IRQ 179                              Microsoft ACPI- 
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                          PCI - PCI
    IRQ 180                              Microsoft ACPI- 
    IRQ 181                              Microsoft ACPI- 
    IRQ 182                              Microsoft ACPI- 
    IRQ 183                              Microsoft ACPI- 
    IRQ 184                              Microsoft ACPI- 
    IRQ 185                              Microsoft ACPI- 
    IRQ 186                              Microsoft ACPI- 
    IRQ 187                              Microsoft ACPI- 
    IRQ 188                              Microsoft ACPI- 
    IRQ 189                              Microsoft ACPI- 
    IRQ 19                                          PCI - USB -
    IRQ 19                                         High Definition Audio (Microsoft)
    IRQ 190                              Microsoft ACPI- 
    IRQ 22                                        AMD SATA Controller (IDE Mode)
    IRQ 65536                            AMD Radeon R7 240 Series
    IRQ 81                               Microsoft ACPI- 
    IRQ 82                               Microsoft ACPI- 
    IRQ 83                               Microsoft ACPI- 
    IRQ 84                               Microsoft ACPI- 
    IRQ 85                               Microsoft ACPI- 
    IRQ 86                               Microsoft ACPI- 
    IRQ 87                               Microsoft ACPI- 
    IRQ 88                               Microsoft ACPI- 
    IRQ 89                               Microsoft ACPI- 
    IRQ 90                               Microsoft ACPI- 
    IRQ 91                               Microsoft ACPI- 
    IRQ 92                               Microsoft ACPI- 
    IRQ 93                               Microsoft ACPI- 
    IRQ 94                               Microsoft ACPI- 
    IRQ 95                               Microsoft ACPI- 
    IRQ 96                               Microsoft ACPI- 
    IRQ 97                               Microsoft ACPI- 
    IRQ 98                               Microsoft ACPI- 
    IRQ 99                               Microsoft ACPI- 
     00000000-0009FFFF              
     000A0000-000BFFFF                       PCI
     000A0000-000BFFFF                      AMD Radeon R7 240 Series
     000A0000-000BFFFF                 PCI - PCI
     000C0000-000CFFFF              
     000D0000-000DFFFF                       PCI
     000E0000-000FFFFF              
     00100000-CFEFFFFF              
     CFF00000-CFFFFFFF               
     CFF00000-DFFFFFFF                       PCI
     D0000000-DFFFFFFF               PCI - PCI
     D0000000-DFFFFFFF             AMD Radeon R7 240 Series
     E0000000-EFFFFFFF               
     F0000000-FEBFFFFF                       PCI
     FE9F4000-FE9F7FFF              High Definition Audio (Microsoft)
     FE9FA000-FE9FAFFF              OpenHCD USB -
     FE9FB000-FE9FBFFF              OpenHCD USB -
     FE9FC000-FE9FCFFF              OpenHCD USB -
     FE9FD000-FE9FDFFF              OpenHCD USB -
     FE9FE000-FE9FEFFF              OpenHCD USB -
     FE9FF400-FE9FF4FF               PCI - USB -
     FE9FF800-FE9FF8FF               PCI - USB -
     FE9FFC00-FE9FFFFF             AMD SATA Controller (IDE Mode)
     FEA00000-FEAFFFFF               PCI - PCI
     FEA9C000-FEA9FFFF              High Definition Audio (Microsoft)
     FEAC0000-FEAFFFFF             AMD Radeon R7 240 Series
     FEB00000-FEBFFFFF               PCI - PCI
     FEBC0000-FEBFFFFF             Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
     FEC00000-FEC00FFF               
     FEC00000-FFFFFFFF              
     FEC10000-FEC1001F               
     FED00000-FED003FF               
     FED40000-FED44FFF               
     FEE00000-FEE00FFF               
     FFB80000-FFBFFFFF               
     0000-000F                           
     0000-0CF7                                 PCI
     0010-001F                         
     0020-0021                         
     0022-003F                         
     0040-0043                        
     0060-0060                         
     0060-0060                         
     0061-0061                        
     0062-0063                         
     0064-0064                         
     0064-0064                         
     0065-006F                         
     0070-0071                       CMOS  
     0072-007F                         
     0080-0080                         
     0081-0083                           
     0084-0086                         
     0087-0087                           
     0088-0088                         
     0089-008B                           
     008C-008E                         
     008F-008F                           
     0090-009F                         
     00A0-00A1                         
     00A2-00BF                         
     00B1-00B1                         
     00C0-00DF                           
     00E0-00EF                         
     00F0-00FF                        
     0170-0177                       ATA Channel 1
     01F0-01F7                       ATA Channel 0
     0230-023F                         
     0290-029F                         
     0300-030F                         
     0376-0376                       ATA Channel 1
     03B0-03BB                                AMD Radeon R7 240 Series
     03B0-03BB                           PCI - PCI
     03C0-03DF                                AMD Radeon R7 240 Series
     03C0-03DF                           PCI - PCI
     03F6-03F6                       ATA Channel 0
     03F8-03FF                       Nuvoton Communications Port (COM1)
     040B-040B                         
     04D0-04D1                         
     04D6-04D6                         
     0800-089F                         
     0900-090F                         
     0910-091F                         
     0A30-0A3F                         
     0B00-0B0F                         
     0B00-0B3F                         
     0B20-0B3F                         
     0C00-0C01                         
     0C14-0C14                         
     0C50-0C51                         
     0C52-0C52                         
     0C6C-0C6C                         
     0C6F-0C6F                         
     0CD0-0CD1                         
     0CD2-0CD3                         
     0CD4-0CD5                         
     0CD6-0CD7                         
     0CD8-0CDF                         
     0D00-FFFF                                 PCI
     8000-800F                       AMD SATA Controller (IDE Mode)
     9000-9003                       AMD SATA Controller (IDE Mode)
     A000-A007                       AMD SATA Controller (IDE Mode)
     B000-B003                       AMD SATA Controller (IDE Mode)
     C000-C007                       AMD SATA Controller (IDE Mode)
     D000-D0FF                       AMD Radeon R7 240 Series
     D000-DFFF                         PCI - PCI
     E000-EFFF                         PCI - PCI
     EC00-EC7F                       Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
     FE00-FEFE                         
     FF00-FF0F                       AMD PCI IDE Controller


--------[  ]--------------------------------------------------------------------------------------------------------

  [  HID ]

     :
                                       HID
                                           IBM enhanced (101- or 102-key) keyboard
                                     Russian
        ANSI                             1251 -  (Windows)
        OEM                              866 -  (DOS)
                                         1
                                         31

  [ HID-  ]

     :
                                            HID- 
                                         5
                                              
                                         1
                                     500 msec
       X / Y                                       6 / 10
                                 3

     :
                               
                                        
                
                                            
                   
                                              
      Sonar                                             


--------[  ]----------------------------------------------------------------------------------------------------

  [ Fax ]

     :
                                             Fax
                                      
                                  
                                            SHRFAX:
                                         Microsoft Shared Fax Driver (v4.00)
                                           Fax
                                         winprint
                                     
                                             4:00 - 4:00
                                               1
                                 0
                                                  

     :
                                            Letter, 8.5 x 11 in
                                              
                                          200 x 200 dpi Mono

  [ Microsoft XPS Document Writer ( ) ]

     :
                                             Microsoft XPS Document Writer
                                      
                                  
                                            XPSPort:
                                         Microsoft XPS Document Writer (v6.00)
                                           Microsoft XPS Document Writer
                                         winprint
                                     
                                             
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color


--------[  ]------------------------------------------------------------------------------------------------

    RTHDVCPL                           Registry\Common\Run      C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
    SaferVPN                           Registry\User\Run        D:\SaferVPN.exe -startReason:autoLaunchOnBoot


--------[  ]---------------------------------------------------------------------------------------------

  [ Adobe Flash Player NPAPI Notifier ]

     :
                                               Adobe Flash Player NPAPI Notifier
                                                  
                                           C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_371_Plugin.exe
                                     -check plugin
                                            
                                                   Adobe Flash NPAPI Player         .      , Adobe Flash Player            .
                                        Home-\Home
                                               Adobe
                                         06.06.2020 8:41:59
                                         06.06.2020 9:42:00

     :
      Daily                                             At 00:42:00Z every 7 days - After triggered, repeat every 1 hour for a duration of 1 day

  [ Adobe Flash Player PPAPI Notifier ]

     :
                                               Adobe Flash Player PPAPI Notifier
                                                  
                                           C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_371_pepper.exe
                                     -check pepperplugin
                                            
                                                   Adobe Flash PPAPI Player         .      , Adobe Flash Player            .
                                        Home-\Home
                                               Adobe
                                         06.06.2020 8:27:10
                                         06.06.2020 9:14:00

     :
      Daily                                             At 00:14:00Z every 7 days - After triggered, repeat every 1 hour for a duration of 1 day

  [ Adobe Flash Player Updater ]

     :
                                               Adobe Flash Player Updater
                                                  
                                           C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
                                     
                                            
                                                  Adobe Flash Player        .      , Adobe Flash Player           .
                                        
                                               Adobe
                                         06.06.2020 8:46:59
                                         06.06.2020 9:47:00

     :
      Daily                                             At 00:47:00Z every day - After triggered, repeat every 1 hour for a duration of 1 day

  [ AMDLinkUpdate ]

     :
                                               AMDLinkUpdate
                                                  
                                           C:\Program Files\AMD\CIM\BIN64\InstallManagerApp.exe
                                     -AMDLinkUpdate
                                            
                                             AMDLinkUpdate
                                        Home-\Home
                                               Advanced Micro Devices
                                         
                                         

  [ ModifyLinkUpdate ]

     :
                                               ModifyLinkUpdate
                                                  
                                           C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe
                                     -UpdateCurrentUser
                                            
                                             ModifyLinkUpdate
                                        
                                               Advanced Micro Devices
                                         06.06.2020 9:00:44
                                         

     :
      At log on                                         At log on of any user

  [ Opera scheduled Autoupdate 1579626565 ]

     :
                                               Opera scheduled Autoupdate 1579626565
                                                  
                                           D:\launcher.exe
                                     --scheduledautoupdate $(Arg0)
                                            
                                                 Opera.
                                        Home-\Home
                                               Home-\Home
                                         06.06.2020 9:05:44
                                         06.06.2020 20:09:33

     :
      Daily                                             At 20:09:33 every day
      At log on                                         At log on of Home-\Home

  [ StartCN ]

     :
                                               StartCN
                                                  
                                           "C:\Program Files\AMD\CNext\CNext\cncmd.exe"
                                     startwithdelay
                                            
                                             
                                        
                                               WORKGROUP\DESKTOP-THPC04N$
                                         06.06.2020 9:00:44
                                         

     :
      At log on                                         At log on of any user

  [ StartCNBM ]

     :
                                               StartCNBM
                                                  
                                           "C:\Program Files\AMD\CNext\CNext\cncmd.exe"
                                     benchmark
                                            
                                             
                                        
                                               DESKTOP-B8F45TF\Install
                                         07.05.2020 12:07:06
                                         

     :
      One time                                          At 12:07:06 on 07.05.2020

  [ StartDVR ]

     :
                                               StartDVR
                                                  
                                           "C:\Program Files\AMD\CNext\CNext\RSServCmd.exe"
                                     
                                            
                                             
                                        
                                               WORKGROUP\DESKTOP-THPC04N$
                                         06.06.2020 9:00:44
                                         

     :
      At log on                                         At log on of any user


--------[   ]-------------------------------------------------------------------------------------

    Torrent                                                                               3.5.5.45648    uTorrent                                      BitTorrent Inc.                           
    7-Zip 9.30 (x64 edition)                                                                 9.30.00.0    {23170F69-40C1-2702-0930-000001000000}        Igor Pavlov                     2020-01-20
    ACP Application                                                                            1.2.3.5    {6F0FE248-D39D-4150-918F-E76C9E9F5943}        Advanced Micro Devices, Inc.    2020-05-06
    Adobe Flash Player 32 ActiveX                                                           32.0.0.371    Adobe Flash Player ActiveX                    Adobe                                     
    Adobe Flash Player 32 NPAPI                                                             32.0.0.371    Adobe Flash Player NPAPI                      Adobe                                     
    Adobe Flash Player 32 PPAPI                                                             32.0.0.371    Adobe Flash Player PPAPI                      Adobe                                     
    Adobe Shockwave Player + Authorware Web Player                                         v12.0.7.148    Adobe Shockwave Player + Authorware Web Player  Adobe Systems, Inc.                       
    AIDA64                                                                                   6.25.5400    AIDA64                                        FinalWire Ltd.                            
    AIMP3                                                                             v3.55.1338, 31.01.2014    AIMP3                                         AIMP DevTeam                    2020-01-20
    AMD Settings                                                                                 1.0.2    {ACEA819D-2665-4B06-B9FC-E2BDE0F12E20}        Advanced Micro Devices, Inc.    2020-05-06
    AMD Settings                                                                      2020.0421.1645.30151    {235E09F9-2852-4246-B9D8-1E0FBE1FF8EA}        Advanced Micro Devices, Inc.    2020-05-06
    AMD Software                                                                                20.4.2    AMD Catalyst Install Manager                  Advanced Micro Devices, Inc.              
    AMD User Experience Program Installer                                               1950.29.27.421    {91AFCB8E-1D38-4B1E-B75C-9254F7E3DC4B}        Advanced Micro Devices, Inc.    2020-05-06
    Bandicam                                                                                              Bandicam                                      Bandisoft                                 
    Branding64                                                                               1.00.0002    {856DA29A-EA4A-468B-BBC2-B5F60DD75BFE}        Advanced Micro Devices, Inc.    2020-05-06
    Discord                                                                                    0.0.306    Discord                                       Discord Inc.                    2020-42-16
    Epic Games Launcher [ ()]                                                   1.1.267.0    {8468D0B4-D45C-400A-96BA-7D420BE4F628}        Epic Games, Inc.                2020-05-22
    Epic Games Launcher Prerequisites (x64)                                                    1.0.0.0    {66C5838F-B854-4A55-89E6-A6138747A4DF}        Epic Games, Inc.                2020-01-26
    GTA San Andreas                                                                                       GTA San Andreas_is1                           torrent-igruha.org              2020-01-20
    Lagarith Lossless Codec (1.3.27)                                                                      {F59AC46C-10C3-4023-882C-4212A92283B3}_is1                                    2020-01-20
    Launcher Prerequisites (x64)                                                               1.0.0.0    {c6c5a357-c7ca-4a5f-9789-3bb1af579253}        Epic Games, Inc.                          
    Microsoft .NET Framework 4.7.2 (RUS) [ ()]                                  4.7.03062    {86A043D5-87F3-38E2-82BB-4B69A528CC3D}                    2020-03-15
    Microsoft .NET Framework 4.7.2 ()                                                 4.7.03062    {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1049                        
    Microsoft .NET Framework 4.7.2                                                           4.7.03062    {09CCBE8E-B964-30EF-AE84-6537AB4197F9}        Microsoft Corporation           2020-03-15
    Microsoft Silverlight                                                                  5.1.20913.0    {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}        Microsoft Corporation           2020-01-20
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.50727.4053 False                8.0.50727.4053    {B6E3757B-5E77-3915-866A-CCFC4B8D194C}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.50727.42 False                    8.0.50727.42    {6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.51011 False                          8.0.51011    {aac9fcc4-dd9e-4add-901c-b5496a07ab2e}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.56336 False                          8.0.56336    {071c9b48-7c32-4621-a0ac-3f809523288f}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.57102 False                          8.0.57102    {f0cbd694-71ce-4391-9690-5da93b2f0445}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.58298 False                          8.0.58298    {f45b48a7-f616-4211-b927-17cab6a96613}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.59192 False                          8.0.59192    {6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x64 8.0.61000                                8.0.61000    {ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.50727.4053 False                8.0.50727.4053    {770657D0-A123-3C07-8E44-1C83EC895118}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.50727.42 False                    8.0.50727.42    {A49F249F-0C91-497F-86DF-B2585E8E76B7}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.51011 False                          8.0.51011    {a0fe116e-9a8a-466f-aee0-625cb7c207e3}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.56336 False                          8.0.56336    {7299052b-02a4-4627-81f2-1818da5d550d}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.57103 False                          8.0.57103    {d8fea624-4f2c-432d-9a54-6eee9cd1a77e}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.58299 False                          8.0.58299    {052bac4a-6f79-46d4-a024-1ce1b4f73cd4}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.59193 False                          8.0.59193    {837b34e3-7c30-493c-8f6a-2b0f04e2912c}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2005 Redistributable - x86 8.0.61001                                8.0.61001    {710f4c1c-cc18-4c49-8cbf-51240c89a1a2}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 False                          9.0.21022    {350AA351-21FA-3270-8B7A-835434E766AD}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.0 False [ ()]         9.0.21022    {D04659D1-EB2D-3DE5-A833-837A623CCCF7}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022.218 False                  9.0.21022.218    {BBBE35B2-9349-3C48-BD3D-F574B17C7924}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30411 False                          9.0.30411    {D93AC9C8-B6CF-391E-BD2F-48AF4727476C}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 False                          9.0.30729    {4FFA2088-8317-3B14-93CD-4C699DB37843}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.0 False [ ()]         9.0.30729    {2DFD8316-9EF1-3210-908C-4CB61961C1AC}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 False                       9.0.30729    {8220EEFE-38CD-377E-8595-13398D740ACE}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4048 False                9.0.30729.4048    {91415F19-4C22-3609-A105-92ED3522D83C}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 False                9.0.30729.4148    {4B6C7001-C7D6-3710-913E-5BC23FCE91E6}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148.0 False              9.0.30729.4148    {EE936C7A-EA40-31D5-9B65-8E3E089C3828}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.5570 False                9.0.30729.5570    {8338783A-0968-3B85-AFC7-BAAE0A63DC50}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161                      9.0.30729.6161    {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 False                          9.0.21022    {FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.0 False [ ()]         9.0.21022    {DCB46B42-723F-350E-B18A-449BC6C21636}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 False                  9.0.21022.218    {E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 False                          9.0.30411    {5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 False                          9.0.30729    {3C3D696B-0DB7-3C6D-A356-3DB8CE541918}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.0 False [ ()]         9.0.30729    {527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048 False                9.0.30729.4048    {5B1F2843-B379-3FF2-B0D3-64DD143ED53A}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 False                9.0.30729.4148    {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148.0 False              9.0.30729.4148    {002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.5570 False                9.0.30729.5570    {86CE85E6-DBAC-3FFD-B977-E4B79F83C909}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161                      9.0.30729.6161    {9BE518E6-ECC6-35A9-88E4-87755C07200F}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2010 Redistributable - x64 10.0.30319 False                        10.0.30319    {DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219                              10.0.40219    {1D8E6291-B0D5-35EC-8441-6616F567A0F7}        Microsoft Corporation           2020-03-24
    Microsoft Visual C++ 2010 Redistributable - x86 10.0.30319 False                        10.0.30319    {196BB40D-1578-3D01-B289-BEFC77A11A1E}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219                              10.0.40219    {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 False Eng                11.0.61030.0    {ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}        Microsoft Corporation                     
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030                          11.0.61030.0    {a2199617-3609-410f-a8e8-e8806c73545b}                              
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 False Eng                11.0.50727.1    {22154f09-719a-4619-bb71-5b3356999fbf}        Microsoft Corporation                     
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 False                    11.0.50727.1    {6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}                              
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 False Eng                11.0.51106.1    {8e70e4e1-06d7-470b-9f74-a51bef21088e}        Microsoft Corporation                     
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 False                    11.0.51106.1    {615bc16d-60f5-482e-91b3-b51d8130963b}                              
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 False Eng                11.0.60610.1    {95716cce-fc71-413f-8ad5-56c2892d4b3a}        Microsoft Corporation                     
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 False                    11.0.60610.1    {01db25f3-1b76-4d97-88c8-1c90634d88fb}                              
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 False Eng                11.0.61030.0    {33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}        Microsoft Corporation                     
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030                          11.0.61030.0    {f0080ca2-80ae-4958-b6eb-e8fa916d744a}                              
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 False                     11.0.50727    {AC53FC8B-EE18-3F9C-9B59-60937D0B182C}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 False                     11.0.51106    {3C28BFD4-90C7-3138-87EF-418DC16E9598}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 False                     11.0.60610    {764384C5-BCA9-307C-9AAC-FD443662686A}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030                           11.0.61030    {37B8F9C7-03FB-3253-8781-2517C99D7C00}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 False                        11.0.50727    {A2CB1ACB-94A2-32BA-A15E-7D80319F7589}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 False                        11.0.51106    {5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 False                        11.0.60610    {2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030                              11.0.61030    {CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 False                     11.0.50727    {FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 False                     11.0.51106    {6C772996-BFF3-3C8C-860B-B3D48FF05D65}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 False                     11.0.60610    {3D6AD258-61EA-35F5-812C-B7A02152996E}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030                           11.0.61030    {B175520C-86A2-35A7-8619-86DC379688B9}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 False                        11.0.50727    {2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 False                        11.0.51106    {E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 False                        11.0.60610    {E7D4E834-93EB-351F-B8FB-82CDAE623003}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030                              11.0.61030    {BD95A8CD-1D9F-35AD-981A-3E7925026EBB}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 False Eng                12.0.30501.0    {050d4fc8-5d48-4b8f-8972-47c82c46020f}        Microsoft Corporation                     
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501                          12.0.30501.0    {1a63c099-febd-4eaf-83ad-a82ea4fdac49}                              
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 False Eng                12.0.30501.0    {f65db027-aff3-4070-886a-0d87064aabb1}        Microsoft Corporation                     
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501                          12.0.30501.0    {b55f7208-e02b-4828-ac78-59c73ddf5bc7}                              
    Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005                           12.0.21005    {929FBD26-9020-399B-9A7A-751D61F0B942}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005                              12.0.21005    {A749D8E6-B613-3BE3-8F5F-045C84EBA29B}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005                           12.0.21005    {F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005                              12.0.21005    {13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}        Microsoft Corporation           2016-03-12
    Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508                   14.25.28508.3    {6913e92a-b64e-41c9-a5e6-cef39207fe89}        Microsoft Corporation                     
    Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.23.27820                   14.23.27820.0    {45231ab4-69fd-486a-859d-7a59fcd11013}        Microsoft Corporation                     
    Microsoft Visual C++ 2019 X64 Additional Runtime - 14.25.28508                         14.25.28508    {7D0B74C2-C3F8-4AF1-940F-CD79AB4B2DCE}        Microsoft Corporation           2020-06-05
    Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.25.28508                            14.25.28508    {EEA66967-97E2-4561-A999-5C22E3CDE428}        Microsoft Corporation           2020-06-05
    Microsoft Visual C++ 2019 X86 Additional Runtime - 14.23.27820                         14.23.27820    {86BE78D9-65A1-4E69-86F8-C1F5281F8553}        Microsoft Corporation           2020-05-25
    Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.23.27820                            14.23.27820    {00AC3934-26B4-406E-807C-1692AC7329EC}        Microsoft Corporation           2020-05-25
    NVIDIA PhysX                                                                             9.10.0513    {3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}        NVIDIA Corporation              2020-05-22
    Opera Stable 66.0.3515.36                                                             66.0.3515.36    Opera 66.0.3515.36                            Opera Software                            
    PotPlayer v1.5.45995 Stable x86                                                   v1.5.45995 Stable x86    PotPlayer                                     Daum Corp.                                
    PUBG LITE                                                                                  1.0.1.0    PUBG LITE_is1                                                                 2020-03-15
    QuickBinder 1.7                                                                                       QuickBinder 1.7                                                                         
    Realtek High Definition Audio Driver                                                    6.0.1.7179    {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}        Realtek Semiconductor Corp.               
    Rockstar Games Launcher                                                                 1.0.23.252    Rockstar Games Launcher                       Rockstar Games                            
    SAM CoDeC Pack                                                                                5.50    SAM CoDeC Pack                                www.SamLab.ws                             
    Ut Video Codec Suite                                                                        13.3.1    utvideo_is1                                   UMEZAWA Takeshi                 2020-01-20
    WinRAR 5.71 (64-)                                                                  5.71.0    WinRAR archiver                               win.rar GmbH                              
    x264vfw - H.264/MPEG-4 AVC codec (remove only)                                                        x264vfw                                                                                 
    x264vfw - H.264/MPEG-4 AVC codec for x64 (remove only)                                                x264vfw64                                                                               
    Xvid MPEG-4 Video Codec                                                                               Xvid_is1                                                                      2020-01-20


--------[  ]----------------------------------------------------------------------------------------------------

    Microsoft Internet Explorer 11.0.9600.18230                             FJGCP-4DFJD-GJY49-VJBQ7-HYRR2
    Microsoft Windows 7 Ultimate                                            FJGCP-4DFJD-GJY49-VJBQ7-HYRR2


--------[   ]-------------------------------------------------------------------------------------------------

    001               001 Archive                                                      
    386               Virtual Device Driver                                            
    3G2               PotPlayerMini: 3g2                                               video/3gpp2
    3GP               PotPlayerMini: 3gp                                               video/3gpp
    3GP2              PotPlayerMini: 3gp2                                              video/3gpp2
    3GPP              PotPlayerMini: 3gpp                                              video/3gpp
    7Z                7z Archive                                                       
    AAB               Macromedia Authorware 4 AABfile                                  application/x-authorware-bin
    AAC               ADTS Audio                                                       audio/vnd.dlna.adts
    AAM               Macromedia Authorware 4 AAMfile                                  application/x-authorware-map
    AAS               Macromedia Authorware 4 AASfile                                  application/x-authorware-seg
    ADT               ADTS Audio                                                       audio/vnd.dlna.adts
    ADTS              ADTS Audio                                                       audio/vnd.dlna.adts
    AIF               AIFF Format Sound                                                audio/aiff
    AIFC              AIFF Format Sound                                                audio/aiff
    AIFF              AIFF Format Sound                                                audio/aiff
    AMR               PotPlayerMini: amr                                               
    AMV               PotPlayerMini: amv                                               
    ANI               Animated Cursor                                                  
    APPLICATION       Application Manifest                                             application/x-ms-application
    APPREF-MS         Application Reference                                            
    ARJ               arj Archive                                                      
    ASA               ASA File                                                         
    ASF               PotPlayerMini: asf                                               video/x-ms-asf
    ASP               ASP File                                                         
    ASS               PotPlayerMini: ass                                               
    ASX               Windows Media Audio/Video playlist                               video/x-ms-asf
    AU                AU Format Sound                                                  audio/basic
    AVI               PotPlayerMini: avi                                               video/avi
    BAT               Windows Batch File                                               
    BIK               PotPlayerMini: bik                                               
    BLG               Performance Monitor File                                         
    BMP               Bitmap Image                                                     image/bmp
    BZ                 WinRAR                                                     
    BZ2               bz2 Archive                                                      
    BZIP2             bzip2 Archive                                                    
    C2R               C2R File                                                         
    CAB               cab Archive                                                      
    CAMP              WCS Viewing Condition Profile                                    
    CAT               Security Catalog                                                 application/vnd.ms-pki.seccat
    CDA               CD Audio Track                                                   
    CDMP              WCS Device Profile                                               
    CDX               CDX File                                                         
    CER               Security Certificate                                             application/x-x509-ca-cert
    CHESSTITANSSAVE-MS  .ChessTitansSave-ms                                              
    CHK               Recovered File Fragments                                         
    CHM               Compiled HTML Help file                                          
    CMD               Windows Command Script                                           
    COM               MS-DOS Application                                               
    COMFYCAKESSAVE-MS  .ComfyCakesSave-ms                                               
    COMPOSITEFONT     Composite Font File                                              
    CONTACT           Contact File                                                     text/x-ms-contact
    CPIO              cpio Archive                                                     
    CPL               Control Panel Item                                               
    CRD               Information Card                                                 
    CRDS              Information Card Store                                           
    CRL               Certificate Revocation List                                      application/pkix-crl
    CRT               Security Certificate                                             application/x-x509-ca-cert
    CSS               Cascading Style Sheet Document                                   text/css
    CUR               Cursor                                                           
    DB                Data Base File                                                   
    DEB               deb Archive                                                      
    DER               Security Certificate                                             application/x-x509-ca-cert
    DESKLINK          Desktop Shortcut                                                 
    DIAGCAB           Diagnostic Cabinet                                               
    DIAGCFG           Diagnostic Configuration                                         
    DIAGPKG           Diagnostic Document                                              
    DIB               Bitmap Image                                                     image/bmp
    DIVX              PotPlayerMini: divx                                              
    DLL               Application Extension                                            application/x-msdownload
    DMG               dmg Archive                                                      
    DOCX              OOXML Text Document                                              
    DPG               PotPlayerMini: dpg                                               
    DRV               Device Driver                                                    
    DSN               Microsoft OLE DB Provider for ODBC Drivers                       
    DVR               Microsoft Recorded TV Show                                       
    DVR-MS            PotPlayerMini: dvr-ms                                            
    DWFX              XPS Document                                                     model/vnd.dwfx+xps
    EASMX             XPS Document                                                     model/vnd.easmx+xps
    EDRWX             XPS Document                                                     model/vnd.edrwx+xps
    EMF               EMF File                                                         
    EPRTX             XPS Document                                                     model/vnd.eprtx+xps
    EVO               PotPlayerMini: evo                                               
    EVT               EVT File                                                         
    EVTX              EVTX File                                                        
    EXE               Application                                                      application/x-msdownload
    FAT               fat Archive                                                      
    FLV               PotPlayerMini: flv                                               
    FON               Font file                                                        
    FREECELLSAVE-MS   .FreeCellSave-ms                                                 
    GADGET            Windows Gadget                                                   
    GIF               GIF Image                                                        image/gif
    GMMP              WCS Gamut Mapping Profile                                        
    GROUP             Contact Group File                                               text/x-ms-group
    GRP               Microsoft Program Group                                          
    GZ                gz Archive                                                       application/x-gzip
    GZIP              gzip Archive                                                     
    H1C               Windows Help Collection Definition File                          
    H1D               Windows Help Validator File                                      
    H1F               Windows Help Include File                                        
    H1H               Windows Help Merged Hierarchy                                    
    H1K               Windows Help Index File                                          
    H1Q               Windows Help Merged Query Index                                  
    H1S               Compiled Windows Help file                                       
    H1T               Windows Help Table of Contents File                              
    H1V               Windows Help Virtual Topic Definition File                       
    H1W               Windows Help Merged Keyword Index                                
    HEARTSSAVE-MS     .HeartsSave-ms                                                   
    HFS               hfs Archive                                                      
    HLP               Help File                                                        
    HTA               HTML Application                                                 application/hta
    HTM               HTML Document                                                    text/html
    HTML              HTML Document                                                    text/html
    ICC               ICC Profile                                                      
    ICL               Icon Library                                                     
    ICM               ICC Profile                                                      
    ICO               Icon                                                             image/x-icon
    IDX               PotPlayerMini: idx                                               
    IFO               PotPlayerMini: ifo                                               
    IMG               Disc Image File                                                  
    INF               Setup Information                                                
    INI               Configuration Settings                                           
    ISO               iso Archive                                                      
    JFIF              JPEG Image                                                       image/jpeg
    JNT               Journal Document                                                 
    JOB               Task Scheduler Task Object                                       
    JOD               Microsoft.Jet.OLEDB.4.0                                          
    JPE               JPEG Image                                                       image/jpeg
    JPEG              JPEG Image                                                       image/jpeg
    JPG               JPEG Image                                                       image/jpeg
    JS                JavaScript File                                                  
    JSE               JScript Encoded File                                             
    JTP               Journal Template                                                 
    JTX               XPS Document                                                     application/x-jtx+xps
    K3G               PotPlayerMini: k3g                                               
    LABEL             Property List                                                    
    LHA               lha Archive                                                      
    LIBRARY-MS        Library Folder                                                   application/windows-library+xml
    LNK               Shortcut                                                         
    LOG               Text Document                                                    
    LZ                 WinRAR                                                     
    LZH               lzh Archive                                                      
    LZMA              lzma Archive                                                     
    M1V               PotPlayerMini: m1v                                               video/mpeg
    M2T               PotPlayerMini: m2t                                               video/vnd.dlna.mpeg-tts
    M2TS              PotPlayerMini: m2ts                                              video/vnd.dlna.mpeg-tts
    M2V               PotPlayerMini: m2v                                               video/mpeg
    M3U               M3U file                                                         audio/x-mpegurl
    M4A               MPEG-4 Audio                                                     audio/mp4
    M4B               PotPlayerMini: m4b                                               
    M4P               PotPlayerMini: m4p                                               
    M4V               PotPlayerMini: m4v                                               video/mp4
    MAHJONGTITANSSAVE-MS  .MahjongTitansSave-ms                                            
    MAPIMAIL          Mail Service                                                     
    MCL               MCL File                                                         
    MFP               Macromedia Flash Paper                                           application/x-shockwave-flash
    MHT               MHTML Document                                                   message/rfc822
    MHTML             MHTML Document                                                   message/rfc822
    MID               MIDI Sequence                                                    audio/mid
    MIDI              MIDI Sequence                                                    audio/mid
    MIG               Migration Store                                                  
    MINESWEEPERSAVE-MS  .MinesweeperSave-ms                                              
    MKV               PotPlayerMini: mkv                                               
    MLC               Language Pack File_                                              
    MOD               Movie Clip                                                       video/mpeg
    MOV               PotPlayerMini: mov                                               video/quicktime
    MP2               MP3 Format Sound                                                 audio/mpeg
    MP2V              PotPlayerMini: mp2v                                              video/mpeg
    MP3               MP3 Format Sound                                                 audio/mpeg
    MP4               PotPlayerMini: mp4                                               video/mp4
    MP4V              MP4 Video                                                        video/mp4
    MPA               Movie Clip                                                       video/mpeg
    MPE               PotPlayerMini: mpe                                               video/mpeg
    MPEG              PotPlayerMini: mpeg                                              video/mpeg
    MPG               PotPlayerMini: mpg                                               video/mpeg
    MPV2              PotPlayerMini: mpv2                                              video/mpeg
    MSC               Microsoft Common Console Document                                
    MSDVD             MSDVD File                                                       
    MSI               Windows Installer Package                                        
    MSP               Windows Installer Patch                                          
    MSRCINCIDENT      Windows Remote Assistance Invitation                             
    MSSTYLES          Windows Visual Style File                                        
    MSU               Microsoft Update Standalone Package                              
    MTS               PotPlayerMini: mts                                               video/vnd.dlna.mpeg-tts
    MXF               PotPlayerMini: mxf                                               
    MYDOCS            MyDocs Drop Target                                               
    NFO               MSInfo Configuration File                                        
    NSR               PotPlayerMini: nsr                                               
    NSV               PotPlayerMini: nsv                                               
    NTFS              ntfs Archive                                                     
    OCX               ActiveX control                                                  
    ODT               ODT File                                                         
    OGM               PotPlayerMini: ogm                                               
    OGV               PotPlayerMini: ogv                                               
    OSDX              OpenSearch Description File                                      application/opensearchdescription+xml
    OTF               OpenType Font file                                               
    OXPS              Open XPS Document                                                
    P10               Certificate Request                                              application/pkcs10
    P12               Personal Information Exchange                                    application/x-pkcs12
    P7B               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    P7C               Digital ID File                                                  application/pkcs7-mime
    P7M               PKCS #7 MIME Message                                             application/pkcs7-mime
    P7R               Certificate Request Response                                     application/x-pkcs7-certreqresp
    P7S               PKCS #7 Signature                                                application/pkcs7-signature
    PARTIAL           Partial Download                                                 
    PBK               Dial-Up Phonebook                                                
    PERFMONCFG        Performance Monitor Configuration                                
    PFM               Type 1 Font file                                                 
    PFX               Personal Information Exchange                                    application/x-pkcs12
    PIF               Shortcut to MS-DOS Program                                       
    PKO               Public Key Security Object                                       application/vnd.ms-pki.pko
    PNF               Precompiled Setup Information                                    
    PNG               PNG Image                                                        image/png
    PRF               PICS Rules File                                                  application/pics-rules
    PRINTEREXPORT     Printer Migration File                                           
    PS1               PS1 File                                                         
    PS1XML            PS1XML File                                                      
    PSC1              PSC1 File                                                        application/PowerShell
    PSD1              PSD1 File                                                        
    PSM1              PSM1 File                                                        
    PURBLEPAIRSSAVE-MS  .PurblePairsSave-ms                                              
    PURBLESHOPSAVE-MS  .PurbleShopSave-ms                                               
    QDS               Directory Query                                                  
    QT                PotPlayerMini: qt                                                
    R00                WinRAR                                                     
    R01                WinRAR                                                     
    R02                WinRAR                                                     
    R03                WinRAR                                                     
    R04                WinRAR                                                     
    R05                WinRAR                                                     
    R06                WinRAR                                                     
    R07                WinRAR                                                     
    R08                WinRAR                                                     
    R09                WinRAR                                                     
    R10                WinRAR                                                     
    R11                WinRAR                                                     
    R12                WinRAR                                                     
    R13                WinRAR                                                     
    R14                WinRAR                                                     
    R15                WinRAR                                                     
    R16                WinRAR                                                     
    R17                WinRAR                                                     
    R18                WinRAR                                                     
    R19                WinRAR                                                     
    R20                WinRAR                                                     
    R21                WinRAR                                                     
    R22                WinRAR                                                     
    R23                WinRAR                                                     
    R24                WinRAR                                                     
    R25                WinRAR                                                     
    R26                WinRAR                                                     
    R27                WinRAR                                                     
    R28                WinRAR                                                     
    R29                WinRAR                                                     
    RAM               PotPlayerMini: ram                                               
    RAR               rar Archive                                                      
    RAT               Rating System File                                               application/rat-file
    RDP               Remote Desktop Connection                                        
    REG               Registration Entries                                             
    RESMONCFG         Resource Monitor Configuration                                   
    REV                RAR                                         
    RLE               RLE File                                                         
    RLL               Application Extension                                            
    RM                PotPlayerMini: rm                                                
    RMI               MIDI Sequence                                                    audio/mid
    RMVB              PotPlayerMini: rmvb                                              
    RPM               PotPlayerMini: rpm                                               
    RTF               Rich Text Document                                               
    RV                PotPlayerMini: rv                                                
    SCF               Windows Explorer Command                                         
    SCP               Text Document                                                    
    SCR               Screen saver                                                     
    SCT               Windows Script Component                                         text/scriptlet
    SEARCHCONNECTOR-MS  Search Connector Folder                                          application/windows-search-connector+xml
    SEARCH-MS         Saved Search                                                     
    SFCACHE           ReadyBoost Cache File                                            
    SKM               PotPlayerMini: skm                                               
    SLUPKG-MS         XrML Digital License Package                                     application/x-ms-license
    SMI               PotPlayerMini: smi                                               
    SND               AU Format Sound                                                  audio/basic
    SOLITAIRESAVE-MS  .SolitaireSave-ms                                                
    SPC               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    SPIDERSOLITAIRESAVE-MS  .SpiderSolitaireSave-ms                                          
    SPL               Shockwave Flash Object                                           application/futuresplash
    SQUASHFS          squashfs Archive                                                 
    SRT               PotPlayerMini: srt                                               
    SSA               PotPlayerMini: ssa                                               
    SST               Microsoft Serialized Certificate Store                           application/vnd.ms-pki.certstore
    STL               Certificate Trust List                                           application/vnd.ms-pki.stl
    SUB               PotPlayerMini: sub                                               
    SVG               SVG Document                                                     image/svg+xml
    SWF               Shockwave Flash Object                                           application/x-shockwave-flash
    SWM               swm Archive                                                      
    SYMLINK           .symlink                                                         
    SYS               System file                                                      
    TAR               tar Archive                                                      application/x-tar
    TAZ               taz Archive                                                      
    TBZ               tbz Archive                                                      
    TBZ2              tbz2 Archive                                                     
    TGZ               tgz Archive                                                      application/x-compressed
    THEME             Windows Theme File                                               
    THEMEPACK         Windows Theme Pack                                               
    TIF               TIF File                                                         image/tiff
    TIFF              TIFF File                                                        image/tiff
    TLZ                WinRAR                                                     
    TP                PotPlayerMini: tp                                                
    TPR               PotPlayerMini: tpr                                               
    TPZ               tpz Archive                                                      
    TRP               PotPlayerMini: trp                                               
    TS                PotPlayerMini: ts                                                video/vnd.dlna.mpeg-tts
    TTC               TrueType Collection Font file                                    
    TTF               TrueType Font file                                               
    TTS               MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TVC               TVC File                                                         
    TVLINK            TVLINK File                                                      
    TVS               TVS File                                                         
    TXT               Text Document                                                    text/plain
    TXZ               txz Archive                                                      
    UDL               Microsoft Data Link                                              
    URL               URL File                                                         
    UU                 WinRAR                                                     
    UUE                WinRAR                                                     
    VBE               VBScript Encoded File                                            
    VBS               VBScript Script File                                             
    VCF               vCard File                                                       text/x-vcard
    VHD               vhd Archive                                                      
    VOB               PotPlayerMini: vob                                               
    VXD               Virtual Device Driver                                            
    WAB               Address Book File                                                
    WAV               Wave Sound                                                       audio/wav
    WAX               Windows Media Audio shortcut                                     audio/x-ms-wax
    WBCAT             Windows Backup Catalog File                                      
    WCX               Workspace Configuration File                                     
    WDP               Windows Media Photo                                              image/vnd.ms-photo
    WEBPNP            Web Point And Print File                                         
    WEBSITE           Pinned Site Shortcut                                             application/x-mswebsite
    WIM               wim Archive                                                      
    WM                PotPlayerMini: wm                                                video/x-ms-wm
    WMA               Windows Media Audio file                                         audio/x-ms-wma
    WMD               Windows Media Player Download Package                            application/x-ms-wmd
    WMDB              Windows Media Library                                            
    WMF               WMF File                                                         
    WMP               PotPlayerMini: wmp                                               
    WMS               Windows Media Player Skin File                                   
    WMV               PotPlayerMini: wmv                                               video/x-ms-wmv
    WMX               Windows Media Audio/Video playlist                               video/x-ms-wmx
    WMZ               Windows Media Player Skin Package                                application/x-ms-wmz
    WPL               Windows Media playlist                                           application/vnd.ms-wpl
    WSC               Windows Script Component                                         text/scriptlet
    WSF               Windows Script File                                              
    WSH               Windows Script Host Settings File                                
    WTV               Windows Recorded TV Show                                         
    WTX               Text Document                                                    
    WVX               Windows Media Audio/Video playlist                               video/x-ms-wvx
    XAML              Windows Markup File                                              application/xaml+xml
    XAR               xar Archive                                                      
    XBAP              XAML Browser Application                                         application/x-ms-xbap
    XHT               XHTML Document                                                   application/xhtml+xml
    XHTML             XHTML Document                                                   application/xhtml+xml
    XML               XML Document                                                     text/xml
    XPS               XPS Document                                                     application/vnd.ms-xpsdocument
    XRM-MS            XrML Digital License                                             text/xml
    XSL               XSL Stylesheet                                                   text/xml
    XXE                WinRAR                                                     
    XZ                xz Archive                                                       
    Z                 z Archive                                                        application/x-compress
    ZFSENDTOTARGET    Compressed (zipped) Folder SendTo Target                         
    ZIP               zip Archive                                                      application/x-zip-compressed
    ZIPX               WinRAR                                                     


--------[    ]--------------------------------------------------------------------------------------

  [ Calendar ]

     :
                                                     Calendar
                                                Browse the days of the calendar.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\en-US\gadget.xml

  [ Clock ]

     :
                                                     Clock
                                                Watch the clock in your own time zone or any city in the world.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\en-US\gadget.xml

  [ CPU Meter ]

     :
                                                     CPU Meter
                                                See the current computer CPU and system memory (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\en-US\gadget.xml

  [ Currency ]

     :
                                                     Currency
                                                Convert from one currency to another.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Currency.Gadget\en-US\gadget.xml

  [ Feed Headlines ]

     :
                                                     Feed Headlines
                                                Track the latest news, sports, and entertainment headlines.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\en-US\gadget.xml

  [ Picture Puzzle ]

     :
                                                     Picture Puzzle
                                                Move the pieces of the puzzle and try to put them in order.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\en-US\gadget.xml

  [ Slide Show ]

     :
                                                     Slide Show
                                                Show a continuous slide show of your pictures.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\en-US\gadget.xml

  [ Weather ]

     :
                                                     Weather
                                                See what the weather looks like around the world.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Weather.Gadget\en-US\gadget.xml

  [ Windows Media Center ]

     :
                                                     Windows Media Center
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               MediaCenter.Gadget\ru-RU\gadget.xml

  [ Windows Media Center ]

     :
                                                     Windows Media Center
                                                Play your latest TV recordings, new Internet TV clips, and favorite music and pictures.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               MediaCenter.Gadget\en-US\gadget.xml

  [  ]

     :
                                                     
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Currency.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\ru-RU\gadget.xml

  [   - ]

     :
                                                       -
                                                   ,     .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                      (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                      .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Weather.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                          .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\ru-RU\gadget.xml


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       Service Pack 1
      Winlogon Shell                                    explorer.exe
          (UAC)  
      UAC Remote Restrictions                           
                                   
      Windows Update Agent                              7.6.7601.19161 (win7sp1_gdr.160212-0600)

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  ]---------------------------------------------------------------------------------------------------

    Windows Defender                                6.1.7600.16385                                         ?         ?


--------[  ]--------------------------------------------------------------------------------------------------

     Windows                              6.1.7600.16385  


--------[   ]--------------------------------------------------------------------------------------------

    Microsoft Windows Defender                6.1.7600.16385


--------[   ]--------------------------------------------------------------------------------------

     :
                                      ()
                            (UTC+01:00) , , , 
                               
                                    

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   ?
         (ISO 4217)                RUB
                                      123456789,00 ?
                         -123456789,00 ?

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0409h                                         ()
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\Home\AppData\Roaming
    CommonProgramFiles(x86)   C:\Program Files (x86)\Common Files
    CommonProgramFiles        C:\Program Files (x86)\Common Files
    CommonProgramW6432        C:\Program Files\Common Files
    COMPUTERNAME              HOME-
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\Home
    LOCALAPPDATA              C:\Users\Home\AppData\Local
    LOGONSERVER               \\HOME-
    NUMBER_OF_PROCESSORS      3
    OS                        Windows_NT
    Path                      C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\7-Zip
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_ARCHITEW6432    AMD64
    PROCESSOR_IDENTIFIER      AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
    PROCESSOR_LEVEL           16
    PROCESSOR_REVISION        0503
    ProgramData               C:\ProgramData
    ProgramFiles(x86)         C:\Program Files (x86)
    ProgramFiles              C:\Program Files (x86)
    ProgramW6432              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\Home\AppData\Local\Temp
    TMP                       C:\Users\Home\AppData\Local\Temp
    USERDOMAIN                Home-
    USERNAME                  Home
    USERPROFILE               C:\Users\Home
    windir                    C:\Windows
    windows_tracing_flags     3
    windows_tracing_logfile   C:\BVTBin\Tests\installpackage\csilogfile.log


--------[   ]-------------------------------------------------------------------------------------------

    Flash Player                                Flash Player


--------[  ]-----------------------------------------------------------------------------------------------------

    C:            0         0      ?  ?
    D:            0         0      ?  ?


--------[   ]---------------------------------------------------------------------------------------------

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1
    [MCI Extensions.BAK]
    3g2=MPEGVideo
    3gp=MPEGVideo
    3gp2=MPEGVideo
    3gpp=MPEGVideo
    aac=MPEGVideo
    adt=MPEGVideo
    adts=MPEGVideo
    m2t=MPEGVideo
    m2ts=MPEGVideo
    m2v=MPEGVideo
    m4a=MPEGVideo
    m4v=MPEGVideo
    mod=MPEGVideo
    mov=MPEGVideo
    mp4=MPEGVideo
    mp4v=MPEGVideo
    mts=MPEGVideo
    ts=MPEGVideo
    tts=MPEGVideo

  [ hosts ]

    
    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\Home\AppData\Roaming
    Cache                        C:\Users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files
    CD Burning                   C:\Users\Home\AppData\Local\Microsoft\Windows\Burn\Burn
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\Home\Favorites
    Common Files (x86)           C:\Program Files (x86)\Common Files
    Common Files                 C:\Program Files\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\Home\AppData\Roaming\Microsoft\Windows\Cookies
    Desktop                      C:\Users\Home\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\Home\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\Home\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\Home\AppData\Local
    My Documents                 C:\Users\Home\Documents
    My Music                     C:\Users\Home\Music
    My Pictures                  C:\Users\Home\Pictures
    My Video                     C:\Users\Home\Videos
    NetHood                      C:\Users\Home\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\Home\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\Home
    Program Files (x86)          C:\Program Files (x86)
    Program Files                C:\Program Files
    Programs                     C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\Home\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\Home\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System (x86)                 C:\Windows\SysWOW64
    System                       C:\Windows\system32
    Temp                         C:\Users\Home\AppData\Local\Temp\
    Templates                    C:\Users\Home\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                         2020-05-30 19:16:36                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-05-31 08:30:05                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                 100        2020-05-31 09:11:03                                  Application Error               1000:   : arizona-launcher.exe, : 0.0.0.0,  : 0x5eb1a0b0    : ntdll.dll, : 6.1.7601.19160,   0x56bcd51f   : 0xc0000005   : 0x0002e546    : 0xebc     : 0x01d63712317c0688    : D:\ARIZONA GAMES\arizona-launcher.exe    : C:\Windows\SysWOW64\ntdll.dll   : 815d57bd-a305-11ea-a0ef-6045cba49e18
                 100        2020-05-31 09:11:28                                  Application Error               1000:   : arizona-launcher.exe, : 0.0.0.0,  : 0x5eb1a0b0    : ntdll.dll, : 6.1.7601.19160,   0x56bcd51f   : 0xc0000005   : 0x0002e546    : 0xe14     : 0x01d637124c4f6879    : D:\ARIZONA GAMES\arizona-launcher.exe    : C:\Windows\SysWOW64\ntdll.dll   : 8fe37d26-a305-11ea-a0ef-6045cba49e18
                 100        2020-05-31 09:24:19                                  Application Error               1000:   : arizona-launcher.exe, : 0.0.0.0,  : 0x5eb1a0b0    : ntdll.dll, : 6.1.7601.19160,   0x56bcd51f   : 0xc0000005   : 0x0002e546    : 0x630     : 0x01d63713c5417af6    : D:\ARIZONA GAMES\arizona-launcher.exe    : C:\Windows\SysWOW64\ntdll.dll   : 5bd48df2-a307-11ea-a0ef-6045cba49e18
                 100        2020-05-31 18:19:38                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x5ec6c440    : tier0.dll, : 0.0.0.0,   0x5e83a221   : 0xc0000005   : 0x000092b1    : 0x4e4     : 0x01d6375ec37f2fdf    : D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : D:\Steam\steamapps\common\Counter-Strike Global Offensive\bin\tier0.dll   : 24371527-a352-11ea-a0ef-6045cba49e18
                         2020-05-31 20:14:20                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-01 08:57:33                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-02 09:45:27                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                 100        2020-06-02 17:19:32                                  Application Error               1000:   : Browserupdphenix.exe, : 0.0.0.0,  : 0x5df9c46b    : Browserupdphenix.exe, : 0.0.0.0,   0x5df9c46b   : 0x40000015   : 0x000460f3    : 0x11c0     : 0x01d638e6de2d92ad    : C:\Users\Home\AppData\Local\Browserupdphenix\Browserupdphenix.exe    : C:\Users\Home\AppData\Local\Browserupdphenix\Browserupdphenix.exe   : 134139c1-a4dc-11ea-b7d3-6045cba49e18
                 100        2020-06-02 19:47:51                                  Application Error               1000:   : gta_sa.exe, : 0.0.0.0,  : 0x437101ca    : samp.dll, : 0.3.7.1,   0x59c30c94   : 0xc0000005   : 0x000abef6    : 0x8c0     : 0x01d638fd875161be    : D:\GTA San Andreas\gta_sa.exe    : D:\GTA San Andreas\samp.dll   : cbd88a98-a4f0-11ea-b7d3-6045cba49e18
                         2020-06-03 08:25:54                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-03 13:07:41                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                 100        2020-06-03 13:31:15                                  Application Error               1000:   : PUBGLite-Win64-Shipping.exe, : 1.4.2.681,  : 0x5e941824    : OculusSpatializerWwise.dll_unloaded, : 0.0.0.0,   0x5b90485a   : 0xc0000005   : 0x000007feceb08724    : 0x714     : 0x01d63991134dedaa    : D:\PUBGLite\Client\ShadowTrackerExtra\Binaries\Win64\PUBGLite-Win64-Shipping.exe    : OculusSpatializerWwise.dll   : 5a016e23-a585-11ea-b306-6045cba49e18
                         2020-06-03 18:29:33                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-03 18:32:28                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-03 18:53:50                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-03 19:03:40                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-03 19:19:31                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                 100        2020-06-03 19:31:23                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x5ec6c440    : unknown, : 0.0.0.0,   0x00000000   : 0xc0000005   : 0x00000000    : 0xda8     : 0x01d639c429994c63    : D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : unknown   : a911d26e-a5b7-11ea-acde-6045cba49e18
                 100        2020-06-03 19:31:35                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x5ec6c440    : mssmp3.asi, : 0.0.0.0,   0x5344bdc5   : 0xc0000005   : 0x0000b52b    : 0xda8     : 0x01d639c429994c63    : D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : d:\steam\steamapps\common\counter-strike global offensive\bin\mssmp3.asi   : b021c967-a5b7-11ea-acde-6045cba49e18
                 100        2020-06-03 19:39:49                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x5ec6c440    : mssmp3.asi, : 0.0.0.0,   0x5344bdc5   : 0xc0000094   : 0x000013d7    : 0x4f8     : 0x01d639c47a8b761f    : D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : d:\steam\steamapps\common\counter-strike global offensive\bin\mssmp3.asi   : d6bb27e1-a5b8-11ea-acde-6045cba49e18
                         2020-06-03 23:06:04                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-03 23:34:15                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 00:44:54                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 08:07:41                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 08:13:53                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 14:35:39                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 20:16:26                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 20:35:43                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 22:58:31                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 23:13:24                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-04 23:53:30                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-05 08:00:00                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-05 08:11:10                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                 100        2020-06-05 08:19:11                                  Application Error               1000:   : mbamservice.exe, : 3.2.0.845,  : 0x5d10ed55    : ScanControllerImpl.dll, : 3.2.0.998,   0x5d016753   : 0xc0000005   : 0x00000000000066d8    : 0x11f8     : 0x01d63af8cf72de29    : C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbamservice.exe    : C:\PROGRAM FILES (X86)\MALWAREBYTES\ANTI-MALWARE\ScanControllerImpl.dll   : 166f7d0b-a6ec-11ea-bca7-6045cba49e18
                 100        2020-06-05 08:20:24                                  Application Error               1000:   : malwarebytes_assistant.exe, : 3.1.0.1838,  : 0x5d13b211    : malwarebytes_assistant.exe, : 3.1.0.1838,   0x5d13b211   : 0xc0000005   : 0x00069110    : 0x5a0     : 0x01d63af8f5aa999b    : C:\Program Files (x86)\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe    : C:\Program Files (x86)\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe   : 41b368a8-a6ec-11ea-bca7-6045cba49e18
                         2020-06-05 08:39:39                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-05 09:01:44                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-05 09:05:15                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-05 16:08:17                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                 100        2020-06-05 20:06:38                                  Application Error               1000:   : GTA5.exe, : 1.0.1868.4,  : 0x5eaae0f1    : GTA5.exe, : 1.0.1868.4,   0x5eaae0f1   : 0x80000003   : 0x0000000001292fff    : 0x130c     : 0x01d63b588d174c4b    : D:\Epic Games\GTAV\GTA5.exe    : D:\Epic Games\GTAV\GTA5.exe   : ea8e913e-a74e-11ea-84ea-6045cba49e18
                         2020-06-05 20:35:08                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-05 20:53:57                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-05 20:59:36                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                 100        2020-06-05 21:01:43                                  Application Error               1000:   : ragemp_v.exe, : 0.0.0.0,  : 0x5ec6475c    : ntdll.dll, : 6.1.7601.19160,   0x56bcd74c   : 0xc0000005   : 0x00000000000183ed    : 0x7a8     : 0x01d63b632bef8531    : D:\RAGEMP\ragemp_v.exe    : C:\Windows\SYSTEM32\ntdll.dll   : 9cdb807a-a756-11ea-9045-6045cba49e18
                 100        2020-06-05 21:23:53                                  Application Error               1000:   : GTA5.exe, : 1.0.1868.4,  : 0x5eaae0f1    : GTA5.exe, : 1.0.1868.4,   0x5eaae0f1   : 0x80000003   : 0x0000000001292fff    : 0xcbc     : 0x01d63b65231f65c7    : D:\Epic Games\GTAV\GTA5.exe    : D:\Epic Games\GTAV\GTA5.exe   : b55e897f-a759-11ea-9045-6045cba49e18
                         2020-06-05 22:06:38                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-05 22:25:42                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-06 08:18:49                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-06 08:30:07                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
                         2020-06-06 09:02:11                                  WinMgmt                         10: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
      Audit Success   12544      2020-05-30 09:09:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 09:09:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 09:11:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 09:11:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 11:07:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 11:07:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 11:10:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 11:10:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 11:17:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 11:17:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 11:21:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 11:21:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 11:26:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 11:26:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 11:28:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 11:28:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 12:02:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 12:02:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 12:09:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 12:09:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 12:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 12:11:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 13:08:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 13:08:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 13:10:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 13:10:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 13:36:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 13:36:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 13:38:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 13:38:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 14:55:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 14:55:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 14:56:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 14:56:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 14:58:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 14:58:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 15:40:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 15:40:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 15:42:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 15:42:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 16:21:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 16:21:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 17:09:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 17:09:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 17:11:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 17:11:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-05-30 19:06:05                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-05-30 19:06:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:06:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:06:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:06:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:06:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-05-30 19:06:05                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9f08  
      Audit Success   12544      2020-05-30 19:06:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:06:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:06:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:06:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:06:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:06:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:06:10                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-05-30 19:06:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x19c59   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:06:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x19c89   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:06:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x19c59    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-05-30 19:06:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-05-30 19:06:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:06:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-05-30 19:06:14                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-05-30 19:06:18                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-05-30 19:06:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x26f39   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:06:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:06:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:06:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:06:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:06:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:06:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-05-30 19:07:12                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x19c89      ,   .  ,  ,  .        .  
      Audit Success   103        2020-05-30 19:07:13                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-05-30 19:09:09                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-05-30 19:09:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-05-30 19:09:09                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9c08  
      Audit Success   12544      2020-05-30 19:09:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:09:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:09:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:09:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:09:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:09:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:09:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:09:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:09:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:09:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:09:14                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-05-30 19:09:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ac06   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:09:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ac36   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:09:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:09:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ac06    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:09:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-05-30 19:09:15                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-05-30 19:09:16                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-05-30 19:09:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x289a4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:09:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:09:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:09:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:09:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-05-30 19:09:43                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ac36      ,   .  ,  ,  .        .  
      Audit Success   103        2020-05-30 19:09:45                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-05-30 19:14:54                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-05-30 19:14:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:14:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:14:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:14:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:14:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-05-30 19:14:54                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9c1f  
      Audit Success   12292      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ade6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ae6a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-30 19:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ade6    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-05-30 19:15:00                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-05-30 19:15:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28541   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-30 19:15:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:15:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:15:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:15:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:15:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:15:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:17:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:17:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:19:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:19:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:23:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:23:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 19:24:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 19:24:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 21:17:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 21:17:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 21:19:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 21:19:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-30 22:14:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-30 22:14:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-05-30 22:17:54                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ae6a      ,   .  ,  ,  .        .  
      Audit Success   103        2020-05-30 22:18:34                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-05-31 08:28:19                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-05-31 08:28:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 08:28:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:28:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-05-31 08:28:19                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7bb  
      Audit Success   12544      2020-05-31 08:28:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:28:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 08:28:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 08:28:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 08:28:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:28:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-31 08:28:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-31 08:28:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-05-31 08:28:24                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-05-31 08:28:24                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-05-31 08:28:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b9be   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 08:28:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ba32   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 08:28:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:28:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b9be    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-31 08:28:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-05-31 08:28:25                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-05-31 08:28:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2c32b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 08:28:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:28:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 08:28:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:28:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 08:30:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:30:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-05-31 08:31:46                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x15c   :  C:\Windows\System32\svchost.exe     :  2020-05-31T05:31:50.931607900Z   :  2020-05-31T05:31:46.685233500Z          .    Windows,    ,    .           .  
      Audit Success   12288      2020-05-31 08:31:46                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x15c   :  C:\Windows\System32\svchost.exe     :  2020-05-31T05:31:46.863236000Z   :  2020-05-31T05:31:46.863000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2020-05-31 08:31:47                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x15c   :  C:\Windows\System32\svchost.exe     :  2020-05-31T05:31:47.009008300Z   :  2020-05-31T05:31:47.009000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2020-05-31 08:33:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:33:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 08:39:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 08:39:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 09:08:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 09:08:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 09:11:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 09:11:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 09:16:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 09:16:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 09:19:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 09:19:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 09:24:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 09:24:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 09:41:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 09:41:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 10:31:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 10:31:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 10:33:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 10:33:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 11:17:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 11:17:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 11:18:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 11:18:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 11:20:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 11:20:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 12:18:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 12:18:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 12:32:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 12:32:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 12:36:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 12:36:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 12:38:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 12:38:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 13:18:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 13:18:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 13:40:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 13:40:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 13:42:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 13:42:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 14:34:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 14:34:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 14:36:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 14:36:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 16:33:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 16:33:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 16:36:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 16:36:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 17:02:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 17:02:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 17:33:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 17:33:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 17:47:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 17:47:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 17:50:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 17:50:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 18:15:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 18:15:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 18:19:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 18:19:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 18:35:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 18:35:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 18:37:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 18:37:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-05-31 20:12:38                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-05-31 20:12:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 20:12:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 20:12:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:12:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-31 20:12:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-05-31 20:12:38                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa1fa  
      Audit Success   12544      2020-05-31 20:12:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 20:12:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 20:12:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:12:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-31 20:12:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-31 20:12:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-05-31 20:12:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-05-31 20:12:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 20:12:43                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-05-31 20:12:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1af39   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 20:12:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1afa2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2cc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:12:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-05-31 20:12:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1af39    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-05-31 20:12:47                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-05-31 20:12:50                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-05-31 20:12:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x299e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-05-31 20:12:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:12:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 20:13:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:13:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 20:13:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:13:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 20:14:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:14:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 20:16:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:16:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-05-31 20:21:07                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x12c   :  C:\Windows\System32\svchost.exe     :  2020-05-31T17:21:07.170853300Z   :  2020-05-31T17:21:07.170000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2020-05-31 20:59:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 20:59:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 21:16:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 21:16:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 21:19:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 21:19:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 22:15:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 22:15:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 22:17:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 22:17:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 23:16:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 23:16:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 23:19:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 23:19:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-05-31 23:39:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-05-31 23:39:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-05-31 23:47:45                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1afa2      ,   .  ,  ,  .        .  
      Audit Success   103        2020-05-31 23:48:07                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-01 08:55:44                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-01 08:55:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-01 08:55:44                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa078  
      Audit Success   12544      2020-06-01 08:55:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-01 08:55:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 08:55:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-01 08:55:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 08:55:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-01 08:55:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-01 08:55:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 08:55:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-01 08:55:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-01 08:55:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-01 08:55:49                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-01 08:55:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-01 08:55:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-01 08:55:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1cbb9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-01 08:55:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1cc28   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 08:55:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-01 08:55:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1cbb9    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-01 08:55:51                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-01 08:55:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x25e1b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-01 08:55:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 08:55:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 08:56:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 08:56:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 08:57:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 08:57:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 08:59:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 08:59:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 09:00:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 09:00:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 09:03:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 09:03:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 10:58:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 10:58:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 11:01:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 11:01:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 11:58:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 11:58:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 12:01:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 12:01:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 12:48:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 12:48:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 12:59:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 12:59:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 13:01:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 13:01:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 13:24:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 13:24:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 13:27:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 13:27:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 14:02:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 14:02:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 14:05:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 14:05:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 14:10:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 14:10:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 14:15:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 14:15:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 14:22:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 14:22:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 14:59:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 14:59:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 15:02:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 15:02:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 15:23:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 15:23:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 15:25:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 15:25:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 15:27:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 15:27:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 17:00:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 17:00:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 17:02:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 17:02:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 18:02:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 18:02:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 18:05:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 18:05:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 18:18:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 18:18:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 18:24:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 18:24:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 18:26:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 18:26:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 19:00:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 19:00:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 19:02:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 19:02:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 19:39:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 19:39:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 19:52:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 19:52:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 19:54:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 19:54:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 21:01:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 21:01:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-01 21:03:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-01 21:03:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-01 22:31:45                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1cc28      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-01 22:32:08                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-02 09:43:47                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-02 09:43:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-02 09:43:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-02 09:43:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 09:43:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-02 09:43:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-02 09:43:47                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa4a8  
      Audit Success   12544      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b7f1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b841   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-02 09:43:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b7f1    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-02 09:43:52                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-02 09:43:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 09:43:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-02 09:43:54                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-02 09:43:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2d66e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-02 09:44:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 09:44:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 09:44:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 09:44:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 09:46:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 09:46:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 09:48:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 09:48:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 11:46:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 11:46:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 11:49:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 11:49:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 12:48:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 12:48:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 12:51:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 12:51:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 12:58:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 12:58:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 13:10:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 13:10:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 13:13:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 13:13:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 13:15:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 13:15:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 13:20:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 13:20:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 13:47:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 13:47:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 13:50:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 13:50:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 13:55:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 13:55:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 15:48:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 15:48:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 15:50:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 15:50:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 16:20:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 16:20:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 16:24:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 16:24:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 16:29:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 16:29:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 17:19:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 17:19:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 17:49:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 17:49:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 17:51:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 17:51:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 18:00:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 18:00:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 18:23:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 18:23:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 18:25:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 18:25:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 18:29:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 18:29:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 18:56:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 18:56:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 18:58:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 18:58:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 19:18:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 19:18:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 19:20:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 19:20:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 19:45:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 19:45:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 19:49:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 19:49:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 19:51:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 19:51:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 19:53:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 19:53:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 19:56:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 19:56:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 20:08:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 20:08:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 20:17:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 20:17:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 20:19:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 20:19:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 21:50:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 21:50:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 21:52:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 21:52:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 22:21:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 22:21:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 22:25:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 22:25:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-02 23:36:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-02 23:36:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-02 23:37:57                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b841      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-02 23:38:40                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-03 08:24:10                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 08:24:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 08:24:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 08:24:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 08:24:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 08:24:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 08:24:10                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa37d  
      Audit Success   12292      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d86d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d997   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 08:24:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d86d    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 08:24:16                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 08:24:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28ffd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 08:24:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 08:24:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 08:24:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 08:24:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 08:26:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 08:26:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 08:29:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 08:29:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 09:42:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 09:42:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 09:44:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 09:44:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 10:27:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 10:27:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 10:30:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 10:30:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 10:45:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 10:45:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 10:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 10:47:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 11:28:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 11:28:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 11:31:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 11:31:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 12:29:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 12:29:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 12:32:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 12:32:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 12:32:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 12:32:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 12:44:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 12:44:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-03 13:02:01                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d997      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-03 13:02:25                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-03 13:05:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 13:05:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-03 13:05:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9d35  
      Audit Success   12544      2020-06-03 13:06:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 13:06:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:06:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 13:06:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 13:06:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:06:05                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 13:06:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bfd3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 13:06:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c039   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:06:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bfd3    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 13:06:07                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 13:06:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29358   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 13:06:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:06:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:06:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:06:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:06:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:06:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:08:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:08:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:10:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:10:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:23:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:23:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:27:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:27:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:29:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:29:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:31:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:31:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 13:48:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 13:48:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 14:06:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 14:06:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 14:06:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 14:06:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 14:06:39                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x2fc    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x4f05f7  
      Audit Success   13568      2020-06-03 14:06:39                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x2fc    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x4f05f7  
      Audit Success   12544      2020-06-03 14:08:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 14:08:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 14:12:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 14:12:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 14:14:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 14:14:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 14:49:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 14:49:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 14:51:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 14:51:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:06:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:06:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:09:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:09:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:11:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:11:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:12:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:12:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:33:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:33:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:36:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:36:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:38:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:38:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:55:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 15:55:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:55:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 15:55:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 15:58:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 15:58:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 16:01:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 16:01:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 16:07:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 16:07:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 17:09:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 17:09:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 17:11:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 17:11:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:11:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:11:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:13:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:13:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-03 18:27:55                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 18:27:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:27:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:27:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:27:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:27:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 18:27:55                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xabf3  
      Audit Success   12544      2020-06-03 18:27:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:27:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:27:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:27:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:27:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:27:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-03 18:28:05                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-03 18:28:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:28:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:28:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 18:28:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b8e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:28:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b914   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:28:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b8e4    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 18:28:09                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-03 18:28:09                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 18:28:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2405c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:28:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:28:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:28:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:28:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-03 18:30:00                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b914      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-03 18:30:01                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-03 18:30:43                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 18:30:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:30:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:30:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:30:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:30:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 18:30:43                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9f15  
      Audit Success   12544      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1abbd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1abed   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:30:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1abbd    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 18:30:48                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-03 18:30:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:30:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 18:30:50                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 18:30:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29445   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:30:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:30:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:31:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:31:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:33:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:33:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:35:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:35:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:45:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:45:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-03 18:52:09                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 18:52:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:52:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:52:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:52:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:52:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 18:52:09                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa5b7  
      Audit Success   12544      2020-06-03 18:52:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:52:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:52:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:52:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:52:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 18:52:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-03 18:52:19                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-03 18:52:20                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 18:52:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b9fe   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:52:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ba31   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:52:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b9fe    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 18:52:22                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-03 18:52:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:52:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 18:52:23                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 18:52:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x26f19   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 18:52:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:52:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:52:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:52:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:55:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:55:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 18:57:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 18:57:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-03 19:01:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 19:01:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-03 19:01:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa86c  
      Audit Success   12544      2020-06-03 19:02:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:02:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:02:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 19:02:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:02:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:02:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:02:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:02:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:02:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 19:02:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-03 19:02:10                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-03 19:02:12                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 19:02:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bac2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:02:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1baf6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:02:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bac2    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:02:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:02:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 19:02:14                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-03 19:02:14                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 19:02:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2649f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:02:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:02:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:02:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:02:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:04:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:04:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:04:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:04:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:06:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:06:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-03 19:17:06                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1baf6      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-03 19:17:07                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-03 19:17:46                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 19:17:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:17:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:17:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:17:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 19:17:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 19:17:46                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9fb6  
      Audit Success   12544      2020-06-03 19:17:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:17:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:17:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:17:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 19:17:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 19:17:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:17:51                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 19:17:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d03c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:17:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d077   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:17:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:17:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d03c    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 19:17:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 19:17:52                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-03 19:17:53                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 19:17:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27907   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 19:18:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:18:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:18:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:18:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:20:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:20:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:22:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:22:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:22:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:22:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:31:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:31:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:39:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:39:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:56:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:56:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 19:56:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 19:56:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 19:56:35                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x55c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x21702d  
      Audit Success   13568      2020-06-03 19:56:35                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x55c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x21702d  
      Audit Success   12544      2020-06-03 20:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 20:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 20:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 20:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 20:16:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 20:16:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 20:27:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 20:27:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 20:27:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 20:27:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 20:27:56                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x7a8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x4a5a2c  
      Audit Success   13568      2020-06-03 20:27:56                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x7a8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x4a5a2c  
      Audit Success   12544      2020-06-03 20:48:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 20:48:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 20:48:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 20:48:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 20:49:17                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x1550    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x6c03ed  
      Audit Success   13568      2020-06-03 20:49:17                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x1550    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x6c03ed  
      Audit Success   12544      2020-06-03 21:20:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 21:20:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 21:22:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 21:22:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 22:20:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 22:20:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 22:23:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 22:23:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-03 23:04:25                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 23:04:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:04:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:04:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 23:04:25                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaca7  
      Audit Success   12544      2020-06-03 23:04:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:04:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1aba4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1abd4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1aba4    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:04:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:04:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-03 23:04:33                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-03 23:04:34                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-03 23:04:36                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 23:04:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27701   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:04:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:04:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:05:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:05:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:06:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:06:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:08:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:08:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-03 23:32:32                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-03 23:32:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:32:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:32:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:32:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 23:32:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-03 23:32:32                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa61e  
      Audit Success   12544      2020-06-03 23:32:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:32:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:32:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:32:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 23:32:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 23:32:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:32:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:32:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-03 23:32:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1af5c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:32:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1af8c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:32:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-03 23:32:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1af5c    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-03 23:32:38                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   101        2020-06-03 23:32:39                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-03 23:32:42                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-03 23:32:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28bbc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-03 23:32:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:32:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:33:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:33:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:34:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:34:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-03 23:36:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-03 23:36:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-04 00:43:14                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 00:43:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-04 00:43:14                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa36f  
      Audit Success   12544      2020-06-04 00:43:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 00:43:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 00:43:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 00:43:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 00:43:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 00:43:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 00:43:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 00:43:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 00:43:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 00:43:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 00:43:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 00:43:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d1ba   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 00:43:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d1ea   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 00:43:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d1ba    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-04 00:43:22                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-04 00:43:22                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 00:43:22                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 00:43:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 00:43:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 00:43:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27a85   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 00:43:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 00:43:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 00:43:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 00:43:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 00:46:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 00:46:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-04 00:47:31                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1d1ea      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-04 00:47:32                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-04 08:05:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 08:05:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-04 08:05:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa1e8  
      Audit Success   12544      2020-06-04 08:05:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:05:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:05:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 08:05:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:06:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:06:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:06:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:06:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 08:06:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 08:06:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:06:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 08:06:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ada8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:06:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1add8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:06:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ada8    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:06:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:06:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-04 08:06:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 08:06:08                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 08:06:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b257   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:06:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:06:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:06:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:06:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:06:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:06:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:06:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:06:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:06:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:06:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:07:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:07:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:08:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:08:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 08:08:45                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xc94    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xa58fa  
      Audit Success   13568      2020-06-04 08:08:45                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xc94    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xa58fa  
      Audit Success   12545      2020-06-04 08:08:53                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1add8      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-04 08:08:54                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-04 08:12:13                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 08:12:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:12:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:12:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 08:12:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 08:12:13                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb8c9  
      Audit Success   12544      2020-06-04 08:12:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:12:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:12:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 08:12:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 08:12:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:12:18                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 08:12:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c686   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:12:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c6d3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c686    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-04 08:12:19                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 08:12:19                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 08:12:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:12:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b797   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 08:12:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:12:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:12:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:12:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:12:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:12:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:15:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:15:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 08:17:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 08:17:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 09:53:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 09:53:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 09:56:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 09:56:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 10:13:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 10:13:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 10:15:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 10:15:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 10:17:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 10:17:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 11:15:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 11:15:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 11:17:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 11:17:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 11:44:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 11:44:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 11:46:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 11:46:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 12:15:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 12:15:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 12:17:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 12:17:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 12:50:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 12:50:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 12:53:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 12:53:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:15:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:15:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:17:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:17:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-04 14:29:32                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 14:29:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:29:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:29:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:29:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 14:29:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 14:29:32                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa84a  
      Audit Success   12544      2020-06-04 14:29:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:29:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:29:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:29:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 14:29:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 14:29:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:29:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 14:29:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bb4c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:29:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bb98   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:29:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bb4c    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:29:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:29:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-04 14:29:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 14:29:44                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   101        2020-06-04 14:29:45                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-04 14:29:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x24b05   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:29:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:29:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:30:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:30:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:30:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:30:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:30:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:30:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:30:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:30:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:30:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:30:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-04 14:30:48                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bb98      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-04 14:30:49                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-04 14:33:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 14:33:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-04 14:33:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaeaf  
      Audit Success   12544      2020-06-04 14:34:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:34:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 14:34:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:34:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:34:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:34:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 14:34:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 14:34:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-04 14:34:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 14:34:08                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 14:34:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:34:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 14:34:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1edc7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:34:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ee4b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 14:34:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1edc7    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:34:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29cf5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 14:34:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:34:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:34:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:34:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:34:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:34:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:34:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:36:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:36:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 14:38:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 14:38:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 16:36:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 16:36:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 16:39:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 16:39:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 17:37:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 17:37:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 17:39:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 17:39:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 18:37:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 18:37:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 18:39:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 18:39:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 18:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 18:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 19:02:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 19:02:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-04 20:14:50                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 20:14:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:14:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:14:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:14:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 20:14:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 20:14:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa3c1  
      Audit Success   12544      2020-06-04 20:14:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:14:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:14:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:14:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:14:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 20:14:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:14:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 20:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b27c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b2ac   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b27c    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-04 20:15:02                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-04 20:15:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 20:15:07                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 20:15:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2680d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:15:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:15:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:15:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:15:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:16:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:16:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:16:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 20:16:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 20:16:24                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x688    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x6156e  
      Audit Success   13568      2020-06-04 20:16:24                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x688    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x6156e  
      Audit Success   12544      2020-06-04 20:17:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:17:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:17:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:17:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:19:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:19:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-04 20:33:12                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b2ac      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-04 20:33:13                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-04 20:34:00                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 20:34:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-04 20:34:00                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa40b  
      Audit Success   12544      2020-06-04 20:34:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:34:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:34:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 20:34:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:34:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:34:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:34:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:34:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 20:34:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 20:34:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:34:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:34:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:34:06                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 20:34:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b16f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:34:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b1bb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:34:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b16f    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-04 20:34:07                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 20:34:09                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 20:34:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29f23   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 20:34:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:34:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:34:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:34:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:35:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:35:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:36:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:36:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:38:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:38:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 20:57:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 20:57:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 21:03:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 21:03:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 21:05:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 21:05:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 21:06:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 21:06:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 21:06:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 21:06:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 21:07:26                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xd64    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x413e23  
      Audit Success   13568      2020-06-04 21:07:26                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xd64    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x413e23  
      Audit Success   12544      2020-06-04 21:56:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 21:56:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 22:05:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:05:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 22:07:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:07:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 22:36:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:36:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 22:38:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:38:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-04 22:56:50                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 22:56:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 22:56:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 22:56:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:56:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 22:56:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 22:56:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa728  
      Audit Success   12544      2020-06-04 22:56:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 22:56:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 22:56:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:56:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 22:56:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 22:56:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 22:57:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 22:57:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b8bd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 22:57:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b90a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:57:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b8bd    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 22:57:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:57:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-04 22:57:03                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-04 22:57:04                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 22:57:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 22:57:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28ca8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 22:57:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:57:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 22:57:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:57:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 22:58:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 22:58:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:00:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:00:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-04 23:11:47                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 23:11:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:11:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:11:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:11:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 23:11:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 23:11:47                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xad9f  
      Audit Success   12544      2020-06-04 23:11:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:11:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 23:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:11:53                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x264    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 23:11:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b317   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:11:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b348   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:11:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b317    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:11:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:11:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-04 23:11:55                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-04 23:11:56                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 23:11:58                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 23:12:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29d1a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:12:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:12:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:12:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:12:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:14:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:14:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:16:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:16:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:25:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:25:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-04 23:51:50                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-04 23:51:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-04 23:51:50                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xad51  
      Audit Success   12544      2020-06-04 23:51:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:51:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:51:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 23:51:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:51:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:51:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:51:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:51:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 23:51:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 23:51:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:51:56                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-04 23:51:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ac7f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:51:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1acaf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:51:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:51:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ac7f    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 23:51:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-04 23:51:57                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-04 23:51:58                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-04 23:51:59                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-04 23:52:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29b4a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:52:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:52:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:52:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:52:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:54:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:54:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:56:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-04 23:56:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:56:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-04 23:56:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-04 23:56:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-04 23:56:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-04 23:56:33                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xe7c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xbe240  
      Audit Success   13568      2020-06-04 23:56:33                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xe7c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xbe240  
      Audit Success   12545      2020-06-05 00:13:59                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1acaf      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-05 00:14:00                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-05 07:58:14                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 07:58:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 07:58:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 07:58:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 07:58:14                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa468  
      Audit Success   12544      2020-06-05 07:58:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 07:58:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 07:58:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 07:58:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 07:58:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 07:58:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 07:58:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 07:58:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 07:58:19                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-05 07:58:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 07:58:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 07:58:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b679   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 07:58:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b6e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 07:58:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 07:58:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b679    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 07:58:24                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 07:58:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2627a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 07:58:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 07:58:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 07:58:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 07:58:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:00:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:00:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:00:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:00:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:01:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:01:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:02:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:02:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:05:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:05:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:05:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 08:05:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 08:06:14                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x8dc    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x13ecc5  
      Audit Success   13568      2020-06-05 08:06:14                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0x8dc    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x13ecc5  
      Audit Success   12545      2020-06-05 08:08:44                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b6e4      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-05 08:08:46                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-05 08:09:28                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 08:09:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:09:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:09:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:09:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 08:09:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 08:09:29                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa549  
      Audit Success   12544      2020-06-05 08:09:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:09:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:09:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:09:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 08:09:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 08:09:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 08:09:34                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-05 08:09:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:09:34                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x29c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 08:09:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1cb4d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x29c    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:09:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1cbad   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x29c    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:09:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 08:09:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1cb4d    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 08:09:35                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 08:09:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2aa87   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:09:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:09:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:09:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:09:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:12:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:12:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:14:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:14:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:19:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:19:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-05 08:38:01                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 08:38:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:38:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:38:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:38:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 08:38:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 08:38:01                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xae0a  
      Audit Success   12544      2020-06-05 08:38:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:38:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:38:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:38:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 08:38:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 08:38:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:38:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:38:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-05 08:38:10                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-05 08:38:10                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 08:38:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c39d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:38:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c3cd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:38:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c39d    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 08:38:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-05 08:38:11                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 08:38:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b23d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 08:38:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:38:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:38:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:38:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:40:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:40:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:41:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:41:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:43:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:43:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 08:48:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 08:48:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-05 08:58:57                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c3cd      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-05 08:59:03                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-05 09:00:01                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 09:00:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:00:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:00:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:00:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 09:00:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 09:00:01                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa5c3  
      Audit Success   12544      2020-06-05 09:00:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:00:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:00:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:00:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 09:00:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 09:00:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:00:06                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 09:00:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b38a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:00:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b3ba   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:00:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b38a    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:00:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:00:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 09:00:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-05 09:00:08                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 09:00:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2bd21   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:00:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:00:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:00:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:00:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-05 09:03:38                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 09:03:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-05 09:03:38                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xab82  
      Audit Success   12544      2020-06-05 09:03:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:03:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:03:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 09:03:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:03:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:03:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:03:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:03:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 09:03:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 09:03:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-05 09:03:45                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-05 09:03:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 09:03:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b8c3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:03:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b927   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:03:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b8c3    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:03:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:03:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 09:03:52                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-05 09:03:52                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 09:03:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2934e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:03:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:03:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:04:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:04:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:04:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 09:04:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:04:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 09:04:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:06:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:06:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 09:08:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 09:08:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 11:06:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 11:06:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 11:09:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 11:09:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 11:29:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 11:29:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 11:31:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 11:31:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 12:08:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 12:08:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 12:10:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 12:10:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 13:07:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 13:07:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 13:09:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 13:09:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 15:07:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 15:07:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 15:09:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 15:09:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 15:48:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 15:48:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 15:51:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 15:51:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-05 16:06:36                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 16:06:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 16:06:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 16:06:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:06:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 16:06:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 16:06:36                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaece  
      Audit Success   12544      2020-06-05 16:06:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 16:06:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 16:06:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:06:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 16:06:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 16:06:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-05 16:06:42                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-05 16:06:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 16:06:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 16:06:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b56f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 16:06:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b59f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:06:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 16:06:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b56f    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 16:06:45                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-05 16:06:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 16:06:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29daf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 16:06:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:06:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 16:07:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:07:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 16:08:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:08:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 16:09:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:09:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 16:10:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:10:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 16:21:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 16:21:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 16:21:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 16:21:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 18:04:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 18:04:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 18:05:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 18:05:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 18:07:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 18:07:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 18:47:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 18:47:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 18:49:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 18:49:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 18:49:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 18:49:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 18:49:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 18:49:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 18:50:02                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xf10    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x572337  
      Audit Success   13568      2020-06-05 18:50:02                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xf10    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x572337  
      Audit Success   12544      2020-06-05 18:53:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 18:53:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 19:15:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 19:15:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 19:17:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 19:17:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:06:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:06:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:08:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:08:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:10:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:10:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:17:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:17:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:17:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:17:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:18:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:18:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 20:18:08                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xf4c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xf5a4dc  
      Audit Success   13568      2020-06-05 20:18:08                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  HOME-$     :  WORKGROUP      :  0x3e7    :    : 0xf4c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xf5a4dc  
      Audit Success   12288      2020-06-05 20:33:31                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 20:33:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-05 20:33:31                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa0dc  
      Audit Success   12544      2020-06-05 20:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:33:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:33:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:33:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:33:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:33:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:33:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 20:33:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-05 20:33:43                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 20:33:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ba13   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:33:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ba69   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:33:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:33:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ba13    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:33:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 20:33:44                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   101        2020-06-05 20:33:47                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-05 20:33:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27b7a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:33:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:33:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:34:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:34:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:34:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:34:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:36:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:36:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:38:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:38:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-05 20:39:08                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ba69      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-05 20:39:10                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-05 20:52:15                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 20:52:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-05 20:52:15                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa4f5  
      Audit Success   12544      2020-06-05 20:52:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:52:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:52:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:52:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:52:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:52:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:52:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:52:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:52:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:52:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:52:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:52:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 20:52:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b2a5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:52:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b303   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:52:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:52:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b2a5    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 20:52:22                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-05 20:52:22                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 20:52:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29c68   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:52:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:52:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:52:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:52:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:54:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:54:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:56:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:56:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-05 20:57:08                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b303      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-05 20:57:09                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-05 20:57:50                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 20:57:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:57:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:57:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:57:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:57:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 20:57:50                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa213  
      Audit Success   12544      2020-06-05 20:57:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:57:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:57:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:57:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:57:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 20:57:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:57:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 20:57:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b745   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:57:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b775   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:57:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b745    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 20:57:57                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-05 20:57:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:57:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 20:57:58                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 20:58:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x26545   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 20:58:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:58:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 20:58:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 20:58:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 21:00:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 21:00:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 21:01:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 21:01:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 21:02:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 21:02:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 21:23:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 21:23:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 21:54:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 21:54:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 21:56:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 21:56:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-05 22:04:58                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 22:04:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:04:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:04:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:04:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 22:04:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 22:04:58                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa92b  
      Audit Success   12544      2020-06-05 22:05:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:05:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:05:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:05:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 22:05:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 22:05:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 22:05:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 22:05:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b182   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:05:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b1b2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:05:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:05:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b182    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 22:05:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 22:05:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-05 22:05:07                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 22:05:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x23485   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   101        2020-06-05 22:05:14                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-05 22:05:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:05:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 22:05:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:05:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 22:07:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:07:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 22:09:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:09:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-05 22:24:03                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 22:24:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:24:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:24:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:24:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 22:24:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 22:24:03                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa962  
      Audit Success   12544      2020-06-05 22:24:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:24:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:24:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:24:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 22:24:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 22:24:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 22:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:24:09                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 22:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b26d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b29d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:24:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 22:24:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b26d    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-05 22:24:11                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-05 22:24:12                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-05 22:24:13                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-05 22:24:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x24df6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 22:24:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:24:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 22:24:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:24:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 22:25:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:25:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 22:27:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 22:27:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-05 23:15:33                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-05 23:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 23:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 23:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 23:15:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 23:15:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2020-06-05 23:15:33                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaeb0  
      Audit Success   12544      2020-06-05 23:15:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 23:15:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 23:15:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 23:15:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 23:15:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-05 23:15:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 23:15:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-05 23:15:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ad5e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 23:15:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1adb6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 23:15:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1ad5e    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 23:15:41                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-05 23:15:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 23:15:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-05 23:15:42                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   101        2020-06-05 23:15:48                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-05 23:15:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2884a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-05 23:15:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 23:15:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-05 23:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-05 23:16:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2020-06-05 23:16:15                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1adb6      ,   .  ,  ,  .        .  
      Audit Success   103        2020-06-05 23:16:16                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2020-06-06 08:17:02                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-06 08:17:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-06 08:17:02                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa309  
      Audit Success   12544      2020-06-06 08:17:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:17:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:17:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 08:17:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:17:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:17:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:17:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:17:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:17:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 08:17:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 08:17:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 08:17:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-06 08:17:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2020-06-06 08:17:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-06 08:17:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c625   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:17:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c684   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2dc    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:17:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1c625    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-06 08:17:10                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-06 08:17:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x31579   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:17:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:17:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:17:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:17:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:18:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:18:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:19:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:19:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:21:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:21:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:22:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:22:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-06 08:28:29                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-06 08:28:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-06 08:28:29                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa5cd  
      Audit Success   12544      2020-06-06 08:28:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:28:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:28:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 08:28:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:28:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:28:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:28:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:28:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 08:28:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 08:28:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2020-06-06 08:28:36                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2020-06-06 08:28:36                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-06 08:28:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b193   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:28:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b1c3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2d8    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:28:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1b193    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:28:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:28:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-06 08:28:38                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2020-06-06 08:28:43                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-06 08:28:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2a4a7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 08:28:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:28:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:29:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:29:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:31:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:31:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 08:33:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 08:33:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2020-06-06 09:00:30                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2020-06-06 09:00:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2020-06-06 09:00:30                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa5df  
      Audit Success   12544      2020-06-06 09:00:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 09:00:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 09:00:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 09:00:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 09:00:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 09:00:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 09:00:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 09:00:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 09:00:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 09:00:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 09:00:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 09:00:36                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Home     :  Home-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2020-06-06 09:00:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bd6b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 09:00:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bd9b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : HOME-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 09:00:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2020-06-06 09:00:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3782522593-3537010133-1841462969-1000     :  Home     :  Home-    :  0x1bd6b    :  SeAssignPrimaryTokenPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2020-06-06 09:00:37                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   101        2020-06-06 09:00:39                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2020-06-06 09:00:39                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2020-06-06 09:00:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x26e2b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2020-06-06 09:00:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 09:00:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 09:00:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 09:00:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 09:02:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 09:02:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2020-06-06 09:04:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  HOME-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2020-06-06 09:04:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
                          2020-05-30 13:54:17  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     arizona-recovery.react.domains        DNS.  
                          2020-05-30 13:54:55  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     arizona-ping.react.group        DNS.  
                          2020-05-30 13:55:15  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     arizona-ping.react.group        DNS.  
                            2020-05-30 19:06:09                                  EventLog                        6008:      17:42:49  ?30.?05.?2020  .  
                            2020-05-30 19:06:25                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-05-30 19:09:23                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-05-30 19:15:06                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-05-30 19:17:08                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-05-30 22:18:28                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-05-31 08:28:31                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-05-31 08:30:34                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-05-31 20:12:42                                  EventLog                        6008:      20:10:35  ?31.?05.?2020  .  
                            2020-05-31 20:12:56                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                          2020-05-31 20:13:13  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     www.msftncsi.com        DNS.  
                            2020-05-31 20:14:57                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                          2020-05-31 20:15:53  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     merchandise.opera-api.com        DNS.  
                            2020-05-31 23:48:04                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-01 08:55:57                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-01 08:58:02                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-01 22:32:05                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-02 09:43:59                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-02 09:46:01                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-02 15:13:47                                  Service Control Manager         7009:    (30000 )     "Steam Client Service".  
                            2020-06-02 15:13:47                                  Service Control Manager         7000:     "Steam Client Service" -    %%1053  
                          2020-06-02 15:43:57  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     api.steampowered.com        DNS.  
                          2020-06-02 15:54:21  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     epicgames-download1.akamaized.net        DNS.  
                          2020-06-02 15:54:30  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     api.steampowered.com        DNS.  
                          2020-06-02 15:54:42  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     catalog-public-service-prod06.ol.epicgames.com        DNS.  
                          2020-06-02 15:56:51  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     download3.epicgames.com        DNS.  
                          2020-06-02 15:57:16  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     client-download.steampowered.com        DNS.  
                          2020-06-02 16:16:41  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     download.epicgames.com        DNS.  
                          2020-06-02 16:16:45  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     api.twitch.tv        DNS.  
                          2020-06-02 16:16:47  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     api.steampowered.com        DNS.  
                          2020-06-02 16:17:07  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     cm1-ams1.cm.steampowered.com        DNS.  
                          2020-06-02 16:17:27  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     api.steampowered.com        DNS.  
                          2020-06-02 17:17:31  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     download.epicgames.com        DNS.  
                            2020-06-02 23:38:33                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-03 08:24:21                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 08:26:26                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-03 13:06:11                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 13:08:15                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-03 18:27:59                                  EventLog                        6008:      18:25:49  ?03.?06.?2020  .  
                            2020-06-03 18:28:00                                  BugCheck                        1001:      .   : 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060320-22214-01.
                            2020-06-03 18:28:11                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 18:30:53                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 18:32:57                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-03 18:52:13                                  EventLog                        6008:      18:49:33  ?03.?06.?2020  .  
                            2020-06-03 18:52:16                                  BugCheck                        1001:      .   : 0x000000fc (0xfffff880009ee1d8, 0x80000001d0316963, 0xfffff80000b9ab30, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060320-21387-01.
                            2020-06-03 18:52:27                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 18:54:30                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-03 19:02:05                                  EventLog                        6008:      18:58:59  ?03.?06.?2020  .  
                            2020-06-03 19:02:07                                  BugCheck                        1001:      .   : 0x000000fc (0xfffff88002d691d8, 0x80000001d02bb963, 0xfffff80000b9ab30, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060320-19546-01.
                            2020-06-03 19:02:19                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 19:04:21                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-03 19:17:07                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-03 19:17:58                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 19:20:01                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-03 23:04:31                                  EventLog                        6008:      23:02:50  ?03.?06.?2020  .  
                            2020-06-03 23:04:31                                  BugCheck                        1001:      .   : 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060320-22198-01.
                            2020-06-03 23:04:40                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 23:06:44                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-03 23:32:36                                  EventLog                        6008:      23:31:13  ?03.?06.?2020  .  
                            2020-06-03 23:32:38                                  BugCheck                        1001:      .   : 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060320-18969-01.
                            2020-06-03 23:32:53                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-03 23:34:58                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 00:43:18                                  EventLog                        6008:      0:41:22  ?04.?06.?2020  .  
                            2020-06-04 00:43:21                                  BugCheck                        1001:      .   : 0x0000003d (0xfffff88002f8c030, 0x0000000000000000, 0x0000000000000000, 0xfffff880111f919a).    : C:\Windows\MEMORY.DMP.  : 060420-21044-01.
                            2020-06-04 00:43:35                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 00:45:37                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 00:47:32                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-04 08:06:18                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 08:08:20                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 08:08:54                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-04 08:12:30                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 08:14:44                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 14:29:36                                  EventLog                        6008:      14:28:01  ?04.?06.?2020  .  
                            2020-06-04 14:29:37                                  BugCheck                        1001:      .   : 0x0000003b (0x00000000c0000005, 0xfffff8000313dfd3, 0xfffff8800a3cd1c0, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060420-20997-01.
                            2020-06-04 14:29:50                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 14:34:13                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 14:36:15                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 16:28:55                                  Service Control Manager         7009:    (30000 )     "Steam Client Service".  
                            2020-06-04 16:28:55                                  Service Control Manager         7000:     "Steam Client Service" -    %%1053  
                            2020-06-04 20:14:56                                  EventLog                        6008:      20:13:46  ?04.?06.?2020  .  
                            2020-06-04 20:14:57                                  BugCheck                        1001:      .   : 0x0000007e (0xffffffffc0000005, 0xfffff88003719fc0, 0xfffff880045ae5d8, 0xfffff880045ade30).    : C:\Windows\MEMORY.DMP.  : 060420-24819-01.
                            2020-06-04 20:15:11                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 20:17:14                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 20:33:13                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-04 20:34:14                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 20:36:16                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 22:56:56                                  EventLog                        6008:      22:55:05  ?04.?06.?2020  .  
                            2020-06-04 22:56:57                                  BugCheck                        1001:      .   : 0x00000034 (0x0000000000050853, 0xfffff88003154108, 0xfffff88003153960, 0xfffff80002f0548d).    : C:\Windows\MEMORY.DMP.  : 060420-21824-01.
                            2020-06-04 22:57:11                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 22:59:13                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 23:11:52                                  EventLog                        6008:      23:09:39  ?04.?06.?2020  .  
                            2020-06-04 23:11:52                                  BugCheck                        1001:      .   : 0x0000003b (0x00000000c0000005, 0xfffff800031bf376, 0xfffff88008cca0b0, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060420-22557-01.
                            2020-06-04 23:12:06                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 23:14:07                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-04 23:51:55                                  EventLog                        6008:      23:50:34  ?04.?06.?2020  .  
                            2020-06-04 23:51:55                                  BugCheck                        1001:      .   : 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060420-20638-01.
                            2020-06-04 23:52:11                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-04 23:54:13                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 00:14:00                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-05 07:58:27                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 08:00:36                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                          2020-06-05 08:01:00  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     crl.pki.goog        DNS.  
                            2020-06-05 08:08:46                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-05 08:09:43                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 08:12:02                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 08:19:14                                  Service Control Manager         7031:  Malwarebytes Service   .   1 ().       5000 :  .  
                            2020-06-05 08:38:05                                  EventLog                        6008:      8:36:18  ?05.?06.?2020  .  
                            2020-06-05 08:38:06                                  BugCheck                        1001:      .   : 0x0000004a (0x000000007701d71a, 0x0000000000000002, 0x0000000000000000, 0xfffff88003d0eca0).    : C:\Windows\MEMORY.DMP.  : 060520-23852-01.
                            2020-06-05 08:38:17                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 08:40:32                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 08:59:03                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-05 09:00:14                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 09:03:39                                  Service Control Manager         7000:     "MBAMChameleon" -    %%2  
                            2020-06-05 09:03:42                                  EventLog                        6008:      9:01:46  ?05.?06.?2020  .  
                            2020-06-05 09:03:44                                  BugCheck                        1001:      .   : 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060520-23914-01.
                            2020-06-05 09:03:55                                  Service Control Manager         7026:    ()    :   MBAMSwissArmy  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 09:06:10                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 09:11:20                           Schannel                        36887:      : 20.  
                            2020-06-05 11:42:59                                  DCOM                            10010:   {682159D9-C321-47CA-B3F1-30E36B2EC8B9} DCOM      .
                            2020-06-05 16:06:40                                  EventLog                        6008:      16:05:26  ?05.?06.?2020  .  
                            2020-06-05 16:06:42                                  BugCheck                        1001:      .   : 0x0000007e (0xffffffffc0000005, 0xfffff80002e8345f, 0xfffff8800809d718, 0xfffff8800809cf70).    : C:\Windows\MEMORY.DMP.  : 060520-20638-01.
                            2020-06-05 16:06:56                                  Service Control Manager         7026:    ()    :   SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 16:09:00                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 20:33:42                                  EventLog                        6008:      20:32:26  ?05.?06.?2020  .  
                            2020-06-05 20:33:43                                  BugCheck                        1001:      .   : 0x0000001e (0xffffffffc0000005, 0xfffff88002d8a3b0, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060520-29702-01.
                            2020-06-05 20:33:55                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 20:35:57                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 20:39:10                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-05 20:52:28                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 20:54:29                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 20:57:09                                  Service Control Manager         7034:  "AMD User Experience Program Launcher"  .   (): 1.  
                            2020-06-05 20:58:03                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 21:00:09                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 21:05:56                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:05:59                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:06:03                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:06:06                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:04                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:07                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:11                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:14                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:41                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:44                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:47                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:51                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:56                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:07:59                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:08:02                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:08:06                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:08:30                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:08:33                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:08:36                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 21:08:39                                  Service Control Manager         7000:     "Rockstar Game Library Service" -    %%2  
                            2020-06-05 22:05:02                                  EventLog                        6008:      22:03:08  ?05.?06.?2020  .  
                            2020-06-05 22:05:03                                  BugCheck                        1001:      .   : 0x0000003b (0x00000000c0000005, 0xfffff80002e8c3e2, 0xfffff88006ba5130, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060520-22386-01.
                            2020-06-05 22:05:15                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 22:07:22                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 22:24:07                                  EventLog                        6008:      22:22:47  ?05.?06.?2020  .  
                            2020-06-05 22:24:09                                  BugCheck                        1001:      .   : 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060520-23212-01.
                            2020-06-05 22:24:26                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-05 22:26:27                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-05 23:15:37                                  EventLog                        6008:      23:13:52  ?05.?06.?2020  .  
                            2020-06-05 23:15:39                                  BugCheck                        1001:      .   : 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060520-21902-01.
                            2020-06-05 23:15:56                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-06 08:17:26                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-06 08:19:28                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-06 08:21:13                                  Service Control Manager         7009:    (30000 )     "Steam Client Service".  
                            2020-06-06 08:21:13                                  Service Control Manager         7000:     "Steam Client Service" -    %%1053  
                            2020-06-06 08:28:33                                  EventLog                        6008:      8:26:51  ?06.?06.?2020  .  
                            2020-06-06 08:28:37                                  BugCheck                        1001:      .   : 0x0000001e (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).    : C:\Windows\MEMORY.DMP.  : 060620-23212-01.
                            2020-06-06 08:28:55                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-06 08:31:11                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  
                            2020-06-06 09:00:35                                  EventLog                        6008:      8:59:33  ?06.?06.?2020  .  
                            2020-06-06 09:00:44                                  Service Control Manager         7026:    ()    :   ESProtectionDriver  SaferVPNmmfilter  SaferVPNNetfilter2  
                            2020-06-06 09:02:46                                  Service Control Manager         7000:     "SaferVPN.Service" -    %%2  


--------[   ]-------------------------------------------------------------------------------------------------------

      :
      Borland Database Engine                           -
      Borland InterBase Client                          -
      Easysoft ODBC-InterBase 6                         -
      Easysoft ODBC-InterBase 7                         -
      Firebird Client                                   -
      Jet Engine                                        4.00.9756.0
      MDAC                                              6.1.7601.17514 (win7sp1_rtm.101119-1850)
      ODBC                                              6.1.7601.17514 (win7sp1_rtm.101119-1850)
      MySQL Connector/ODBC                              -
      Oracle Client                                     -
      PsqlODBC                                          -
      Sybase ASE ODBC                                   -

     :
      Borland InterBase Server                          -
      Firebird Server                                   -
      Microsoft SQL Server                              -
      Microsoft SQL Server Compact Edition              -
      Microsoft SQL Server Express Edition              -
      MySQL Server                                      -
      Oracle Server                                     -
      PostgreSQL Server                                 -
      Sybase SQL Server                                 -


--------[  ODBC ]-----------------------------------------------------------------------------------------------

    Driver da Microsoft para arquivos texto (*.txt; *.csv)      odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Driver do Microsoft Access (*.mdb)                          odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.mdb
    Driver do Microsoft dBase (*.dbf)                           odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.dbf,*.ndx,*.mdx
    Driver do Microsoft Excel(*.xls)                            odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.xls
    Driver do Microsoft Paradox (*.db )                         odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.db
    Driver para o Microsoft Visual FoxPro                       vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Access Driver (*.mdb)                             odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.mdb
    Microsoft Access-Treiber (*.mdb)                            odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.mdb
    Microsoft dBase Driver (*.dbf)                              odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.dbf,*.ndx,*.mdx
    Microsoft dBase VFP Driver (*.dbf)                          vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft dBase-Treiber (*.dbf)                             odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.dbf,*.ndx,*.mdx
    Microsoft Excel Driver (*.xls)                              odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.xls
    Microsoft Excel-Treiber (*.xls)                             odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.xls
    Microsoft FoxPro VFP Driver (*.dbf)                         vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft ODBC for Oracle                                   msorcl32.dll        6.1.7601.19135 (win7sp1_gdr.160121-1718)  
    Microsoft Paradox Driver (*.db )                            odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.db
    Microsoft Paradox-Treiber (*.db )                           odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.db
    Microsoft Text Driver (*.txt; *.csv)                        odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Text-Treiber (*.txt; *.csv)                       odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Visual FoxPro Driver                              vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Visual FoxPro-Treiber                             vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    SQL Server                                                  sqlsrv32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  


--------[    ]--------------------------------------------------------------------------------------------

    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1           111245 /
    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1            85715 /
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1            77068 /
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1            68474 /
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1            68050 /
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2            59309 /
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1            54885 /
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2            52263 /
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2            47090 /
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2            45280 /
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1            45200 /
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2            44459 /
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1            42764 /
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1            41312 /
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2            39542 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1            38265 /
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39             35611 /
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2            31589 /
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2            30690 /
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2            27404 /
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2            27235 /
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2            26279 /
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1            24854 /
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2            23639 /
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2            23246 /
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2            21557 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            21290 /
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2            21240 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            21238 /
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1            21178 /
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2            21007 /
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1            20056 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1            19189 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1            18848 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            17754 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1            16602 /
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1            16436 /
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1            15717 /
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2            14716 /
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39             14070 /
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1            13509 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1            13158 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1            11433 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1            11214 /
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2            10581 /
    3x Athlon II X3 450     3215   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2            10463 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2            10204 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             9660 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             9021 /
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2             8734 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             8543 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 8160 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 7992 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             7620 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 7540 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 6560 /
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2             6431 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             6238 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             6013 /
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2             6000 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             5833 /
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2             5392 /
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 5334 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4591 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2             3971 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3938 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 3672 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 3569 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3364 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 3323 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2919 /


--------[    ]---------------------------------------------------------------------------------------------

    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1            93960 /
    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1            87145 /
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1            73605 /
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1            73328 /
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2            65654 /
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1            60036 /
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2            57968 /
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2            53174 /
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1            53051 /
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2            46700 /
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2            45695 /
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1            44521 /
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1            43931 /
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1            40821 /
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2            40019 /
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2            33260 /
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39             33252 /
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2            32976 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1            27387 /
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2            23902 /
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2            23664 /
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1            23651 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1            19577 /
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2            17670 /
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2            17365 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            17092 /
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2            16992 /
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1            16893 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            16676 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1            14837 /
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1            14246 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            13065 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1            12775 /
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1            12475 /
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2            11929 /
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39             10653 /
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2            10227 /
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1            10159 /
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2             9953 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9949 /
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2             9814 /
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1             9323 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8864 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1             8646 /
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2             7921 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1             7706 /
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2             7272 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             7114 /
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2             7091 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7083 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 6734 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 5654 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 5638 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             5518 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             4868 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4829 /
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2             4696 /
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2             4592 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             4260 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4219 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4094 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             4074 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3803 /
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2             3652 /
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 3561 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3154 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 2831 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2             2797 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 2472 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2335 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2327 /


--------[    ]----------------------------------------------------------------------------------------

    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1           103987 /
    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1            95761 /
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1            67171 /
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1            67051 /
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1            66492 /
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1            55043 /
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2            54396 /
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2            51658 /
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2            50972 /
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2            47965 /
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2            42705 /
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1            40993 /
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1            40461 /
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1            38295 /
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2            37901 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1            34718 /
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2            31262 /
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2            30678 /
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39             26791 /
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2            24893 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            24569 /
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1            24464 /
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2            24331 /
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2            23704 /
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2            22688 /
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2            22048 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            21684 /
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2            19590 /
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2            17604 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1            17551 /
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1            17365 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1            17343 /
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1            17256 /
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2            16691 /
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1            15854 /
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39             15829 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            15257 /
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1            14927 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1            14078 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1            14015 /
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2            12460 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1            12113 /
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1            11321 /
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2            11246 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             9653 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1             9482 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8936 /
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2             8441 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 8217 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             7656 /
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2             7609 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7389 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 6278 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 6127 /
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2             5911 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             5510 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 5287 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             4893 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             4777 /
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2             4690 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4551 /
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2             4237 /
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 4194 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4174 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3681 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3269 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2             3145 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 3051 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 3000 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2987 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2576 /


--------[   ]---------------------------------------------------------------------------------------------

    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1       55.2 ns
    Core i7-3770K           3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2       57.1 ns
    Core i7-4770            3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2       58.3 ns
    Core i7-8700K           3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2       59.5 ns
    A10-6800K               4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2       59.9 ns
    Core i7-7700K           4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2       60.1 ns
    Core i7-6700K           4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2       60.5 ns
    FX-8150                 3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2       60.9 ns
    Core i7-4930K           3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2       61.0 ns
    FX-8350                 4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2       61.2 ns
    FX-6100                 3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2       62.5 ns
    A10-5800K               3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2       62.9 ns
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1       63.1 ns
    Core i7-2600            3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1       66.4 ns
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1       66.8 ns
    Core i7-5775C           3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1       67.3 ns
    Core i7-3960X Extreme    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2       67.5 ns
    Athlon II X3 450        3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2       67.6 ns
    Ryzen 9 3950X           3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1       67.9 ns
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1       69.6 ns
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1       70.4 ns
    Core i7-6850K           3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2       70.5 ns
    Ryzen Threadripper 2990WX    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1       71.2 ns
    Core i7-5820K           3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2       72.0 ns
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2       72.5 ns
    Ryzen 7 2700X           3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1       73.1 ns
    Ryzen 5 2400G           3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1       73.8 ns
    Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2       74.0 ns
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2       74.2 ns
    A8-3850                 2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1       76.0 ns
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2       77.0 ns
    Core i7-7800X           3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2       77.1 ns
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11           78.5 ns
    Xeon E5-2670            2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1       79.5 ns
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2       79.8 ns
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15           81.4 ns
    A10-7850K               3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2       82.4 ns
    Atom C3958              2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39        82.4 ns
    Opteron 6274            2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1       82.5 ns
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15           82.6 ns
    Ryzen 7 1800X           3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1       83.5 ns
    Xeon E5-2660 v3         2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1       84.6 ns
    Celeron J4105           1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39        85.8 ns
    Ryzen Threadripper 3970X    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1       86.7 ns
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1        88.1 ns
    Atom D2500              1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2       90.0 ns
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2       91.3 ns
    Celeron J1900           2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1       93.1 ns
    Atom C2750              2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1       94.7 ns
    Atom D525               1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2       95.3 ns
    A12-9800                3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1       96.9 ns
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1       99.5 ns
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1      100.4 ns
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15          101.2 ns
    Celeron J3455           1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1      101.6 ns
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2      104.1 ns
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12          106.5 ns
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1      108.3 ns
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1      112.5 ns
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15          113.4 ns
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15          114.5 ns
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2      119.9 ns
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1      123.5 ns
    Celeron N3150           1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2      123.9 ns
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7         124.7 ns
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12          127.7 ns
    Athlon 5350             2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2      128.2 ns
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2      129.0 ns
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2      138.7 ns
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2      153.6 ns
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1      159.8 ns


--------[ CPU Queen ]---------------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1        276199
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1        216826
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1        149985
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1        146744
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1         99682
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1         93183
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1         85483
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2         72443
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2         67341
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2         64839
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2         62693
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2         62382
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2         59950
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1         56864
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2         55275
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1         54386
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1         53521
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2         48880
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39          47712
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2         47204
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2         46792
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1         45875
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1         43962
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1         42538
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1         42193
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             41733
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         37779
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2         36105
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1         34010
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2         32362
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2         31729
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1         30788
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             26992
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         25503
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1         22146
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             22010
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1         21993
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         21796
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2         21669
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2         21454
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1         21431
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1         21226
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2         20130
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2         19490
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1         19484
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             19232
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39          18844
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1         18011
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1         16868
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2         16621
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         16100
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2         15584
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2         14761
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1         12584
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2         12147
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1         11234
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2          8547
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              7464
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             7287
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2          5916
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2          5444
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1          5165
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          4078
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              4025
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           3855
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12              3791
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          3514
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              3301
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          2815
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2          2586
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2          1839


--------[ CPU PhotoWorxx ]----------------------------------------------------------------------------------------------

    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1          61896 /
    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1          56098 /
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1          38828 /
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2          38788 /
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1          38361 /
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1          35548 /
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2          30449 /
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2          26642 /
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1          24221 /
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1          23753 /
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2          23510 /
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2          23412 /
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2          22800 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1          20497 /
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2          20422 /
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1          19743 /
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2          19369 /
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1          19250 /
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39           17044 /
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1          15634 /
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2          14159 /
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2          14009 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          12969 /
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2          12359 /
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2          12350 /
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2          11904 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          11889 /
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1          11589 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1          11089 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1          10676 /
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2           9568 /
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2           9091 /
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2           8902 /
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1           8800 /
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1           8593 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1           8546 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1           8073 /
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39            7926 /
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1           7765 /
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2           6976 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1           6876 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1           6111 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2           5627 /
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2           5388 /
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1           5276 /
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2           4792 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15               4726 /
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2           4243 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2           4214 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2           3847 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1           3701 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2           3459 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1           3004 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11               2927 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15               2790 /
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2           2536 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               2146 /
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2           1998 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12               1901 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           1895 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2           1869 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15               1864 /
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               1852 /
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2           1788 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7              1676 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           1253 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           1220 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               1102 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            1096 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2            878 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2            831 /


--------[ CPU ZLib ]----------------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1           3233.9 /
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1           2475.9 /
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1           1642.9 /
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1           1216.8 /
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1            977.6 /
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1            751.8 /
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1            685.5 /
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1            672.5 /
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2            575.1 /
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2            544.1 /
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2            493.8 /
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2            453.8 /
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2            437.7 /
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2            432.5 /
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39             415.0 /
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2            407.1 /
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1            365.9 /
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2            359.9 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1            357.7 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            356.9 /
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1            347.3 /
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2            345.2 /
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1            326.0 /
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2            317.0 /
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2            313.7 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1            286.5 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                281.2 /
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2            275.1 /
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2            256.3 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1            243.7 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            224.6 /
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1            209.5 /
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1            189.0 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                188.7 /
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2            186.0 /
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2            183.3 /
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2            174.9 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1            173.8 /
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2            169.8 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2            153.9 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2            151.9 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1            151.4 /
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39             136.0 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                135.1 /
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2            123.0 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                116.8 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2            112.0 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            107.9 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1            105.3 /
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1             99.1 /
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1             97.2 /
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2             95.3 /
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2             84.0 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1             82.8 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             73.7 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             73.2 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 60.0 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                58.4 /
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2             41.7 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             41.5 /
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2             33.3 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             32.8 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 32.2 /
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2             31.7 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              24.0 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             22.6 /
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 19.6 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 18.6 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2             17.4 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             16.1 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             15.3 /


--------[ CPU AES ]-----------------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1   285585 /
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1   224070 /
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1   147445 /
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1    70290 /
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1    65838 /
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1    63242 /
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1    46884 /
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1    38015 /
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1    32074 /
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2    29420 /
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2    27374 /
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2    25198 /
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2    23206 /
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2    21097 /
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2    21096 /
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2    20645 /
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2    18234 /
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39     17940 /
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2    17292 /
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2    16801 /
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1    16358 /
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2    15377 /
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2    14455 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1    13667 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1    12246 /
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2    10337 /
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39      9791 /
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2     9136 /
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1     9011 /
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2     8503 /
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2     8500 /
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2     6557 /
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1     4924 /
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1     4052 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1     3781 /
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2     2908 /
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1     1930 /
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2     1619 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2     1452 /
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2     1332 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1     1286 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15         1233 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1     1152 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1      914 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2      802 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12          791 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1      790 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1      721 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2      663 /
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2      640 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2      587 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15          567 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1      524 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15          494 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1      473 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1      421 /
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1      387 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2      312 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11          277 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7         269 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2      242 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1      153 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15          148 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1       144 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2      131 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2      108 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2      105 /
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2       99 /
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2       98 /
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15           85 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12           44 /


--------[ CPU SHA3 ]----------------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1             9774 /
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1             7396 /
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1             4950 /
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1             4941 /
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2             3419 /
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1             2668 /
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2             2531 /
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1             2524 /
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1             2237 /
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1             2018 /
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2             1986 /
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2             1804 /
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2             1775 /
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2             1569 /
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1             1314 /
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2             1306 /
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1             1283 /
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2             1180 /
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2             1178 /
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2             1136 /
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2             1076 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 1037 /
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39              1031 /
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1              979 /
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2              912 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1              876 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1              845 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1              834 /
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2              796 /
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1              758 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1              736 /
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2              726 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                  684 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1              625 /
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2              625 /
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2              581 /
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2              577 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2              555 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2              547 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1              532 /
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1              525 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1              523 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                  489 /
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2              438 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                  427 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1              418 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2              401 /
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39               385 /
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1              329 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1              327 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1              291 /
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2              272 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2              269 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1              260 /
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1              243 /
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2              213 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                  205 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                 200 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2              146 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                  110 /
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2              107 /
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2              106 /
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2              105 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1                99 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1               96 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2               90 /
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                   73 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2               72 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2               65 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2               51 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                   47 /


--------[ FPU Julia ]---------------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1        302606
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1        149854
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1        141102
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1        111086
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2         66364
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1         62489
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2         54927
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1         40860
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2         40283
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1         38481
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2         38472
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2         36094
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2         34017
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1         30190
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2         28482
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2         27646
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2         26893
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1         24755
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2         19514
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1         18966
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1         18453
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1         18309
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1         18009
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1         17672
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39          15941
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             15291
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2         13498
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2         12633
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1         12205
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2         11912
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         11127
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              8958
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1          8746
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1          8686
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          8203
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          8070
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2          7958
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          7598
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1          7432
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2          7019
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1          6987
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2          6526
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              6416
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2          6228
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39           6169
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2          6093
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1          5655
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              5600
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          5580
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          5577
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2          5235
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1          4053
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          3534
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2          3487
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              2443
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             2388
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1          2308
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          2053
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          1988
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2          1865
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2          1332
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              1307
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2          1112
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               958
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           911
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2           892
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           794
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            701
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           640
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               589
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           513


--------[ FPU Mandel ]--------------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1        160860
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1         79245
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1         72961
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1         54582
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2         36624
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1         32939
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2         29556
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2         21692
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1         21329
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2         20702
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1         20171
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2         19160
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2         18312
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1         15402
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2         15100
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2         14851
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2         14256
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1         12503
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2         10344
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1          9890
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1          9781
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1          9318
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          8675
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1          8614
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              8068
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39           7273
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2          6913
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2          6434
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1          6212
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2          6096
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          5394
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              4625
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1          4421
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          4333
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          4180
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2          4040
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1          3970
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          3874
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1          3646
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2          3454
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39           3349
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              3311
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2          3174
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2          3149
    3x Athlon II X3 450     3215   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2          3105
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1          3068
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1          2981
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              2890
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          2840
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          2675
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2          2335
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1823
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              1482
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             1449
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1          1383
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2          1189
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1          1182
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          1062
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1051
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2           856
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               794
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               494
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2           476
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2           438
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           427
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           406
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2           401
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            359
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           328
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           263
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               193


--------[ FPU SinJulia ]------------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1         55908
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1         46562
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1         28541
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1         18481
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1         16033
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1         13534
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1         12654
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2          7786
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          7470
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2          7272
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2          7240
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2          7218
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2          7116
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1          6993
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1          6821
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2          6511
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1          6131
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2          5460
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2          4978
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2          4826
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2          4714
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1          4675
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1          4658
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1          4615
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          4586
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              4137
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39           3540
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2          3212
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1          3100
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2          2831
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2          2642
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              2589
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          2304
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          2266
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          2221
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1          2210
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1          2042
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          1934
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1          1872
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              1855
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2          1738
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              1618
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1          1575
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2          1546
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2          1480
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2          1478
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          1420
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2          1377
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2          1260
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1          1178
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39           1167
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1049
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1021
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1           974
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11               959
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1           945
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7              942
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2           810
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               516
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           503
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2           463
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2           452
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            359
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           327
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2           284
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               277
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           262
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2           261
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               205
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2           202
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           131


--------[ FP32 Ray-Trace ]----------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1  57482 KRay/s
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1  27881 KRay/s
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1  27293 KRay/s
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1  18503 KRay/s
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2  15902 KRay/s
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2  11818 KRay/s
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1  11356 KRay/s
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1   8389 KRay/s
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2   8264 KRay/s
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2   7481 KRay/s
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1   7408 KRay/s
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2   7282 KRay/s
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2   7266 KRay/s
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1   5988 KRay/s
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2   5195 KRay/s
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2   5054 KRay/s
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2   4853 KRay/s
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1   4789 KRay/s
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1   3691 KRay/s
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2   3562 KRay/s
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1   3360 KRay/s
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1   2868 KRay/s
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1   2653 KRay/s
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2   2599 KRay/s
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1   2559 KRay/s
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39    2556 KRay/s
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2   2541 KRay/s
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15       2182 KRay/s
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2   1982 KRay/s
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1   1911 KRay/s
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2   1642 KRay/s
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1   1629 KRay/s
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1   1546 KRay/s
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2   1379 KRay/s
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2   1369 KRay/s
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12       1313 KRay/s
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2   1252 KRay/s
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1   1215 KRay/s
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1   1212 KRay/s
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2   1175 KRay/s
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2   1161 KRay/s
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1   1129 KRay/s
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1   1104 KRay/s
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39     978 KRay/s
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15        976 KRay/s
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2    950 KRay/s
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15        850 KRay/s
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1    801 KRay/s
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2    788 KRay/s
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1    782 KRay/s
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2    774 KRay/s
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1    570 KRay/s
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2    526 KRay/s
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2    523 KRay/s
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11        370 KRay/s
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7       354 KRay/s
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1    319 KRay/s
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1    299 KRay/s
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2    272 KRay/s
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2    268 KRay/s
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2    213 KRay/s
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15        203 KRay/s
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2    165 KRay/s
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15        145 KRay/s
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1    130 KRay/s
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2    123 KRay/s
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2    117 KRay/s
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1     105 KRay/s
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12         95 KRay/s
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2     92 KRay/s
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2     70 KRay/s


--------[ FP64 Ray-Trace ]----------------------------------------------------------------------------------------------

    32x Ryzen Threadripper 3970X HT    3800   Gigabyte TRX40 Aorus Xtreme                                             TRX40                 Quad DDR4-3200        16-18-18-36 CR1  31857 KRay/s
    16x Ryzen 9 3950X HT    3500   Gigabyte X570 Aorus Pro WiFi                                            X570                  Dual DDR4-3600        16-16-16-36 CR1  15318 KRay/s
    32x Ryzen Threadripper 2990WX HT    3000   MSI MEG X399 Creation                                                   X399                  Quad DDR4-2933        16-18-18-38 CR1  13887 KRay/s
    20x Xeon E5-2660 v3 HT    2600   Supermicro X10DRi                                                       C612                  Octal DDR4-1866       13-13-13-31 CR1  10033 KRay/s
    6x Core i7-7800X HT     3500   Gigabyte X299 UD4                                                       X299                  Quad DDR4-2667        15-17-17-35 CR2   8839 KRay/s
    6x Core i7-8700K HT     3700   Gigabyte Z370 Aorus Gaming 7                                            Z370 Int.             Dual DDR4-2667        16-18-18-38 CR2   6425 KRay/s
    16x Xeon E5-2670 HT     2600   Supermicro X9DR6-F                                                      C600                  Octal DDR3-1333       9-9-9-24 CR1   5969 KRay/s
    4x Core i7-7700K HT     4200   ASRock Z270 Extreme4                                                    Z270 Ext.             Dual DDR4-2133        15-15-15-36 CR2   4564 KRay/s
    8x Ryzen 7 2700X HT     3700   Asus Crosshair VII Hero                                                 X470                  Dual DDR4-2933        16-20-21-49 CR1   4187 KRay/s
    6x Core i7-6850K HT     3600   Asus Strix X99 Gaming                                                   X99                   Quad DDR4-2400        16-16-16-39 CR2   4132 KRay/s
    6x Core i7-5820K HT     3300   Gigabyte GA-X99-UD4                                                     X99                   Quad DDR4-2133        15-15-15-36 CR2   4057 KRay/s
    4x Core i7-6700K HT     4000   Gigabyte GA-Z170X-UD3                                                   Z170 Int.             Dual DDR4-2133        14-14-14-35 CR2   4011 KRay/s
    8x Ryzen 7 1800X HT     3600   Asus Crosshair VI Hero                                                  X370                  Dual DDR4-2667        16-17-17-35 CR1   4000 KRay/s
    32x Opteron 6274        2200   Supermicro H8DGI-F                                                      SR5690                Octal DDR3-1600R      11-11-11-28 CR1   3256 KRay/s
    6x Core i7-4930K HT     3400   Gigabyte GA-X79-UD3                                                     X79                   Quad DDR3-1866        9-10-9-27 CR2   2807 KRay/s
    4x Core i7-4770 HT      3400   Intel DZ87KLT-75K                                                       Z87 Int.              Dual DDR3-1600        9-9-9-27 CR2   2772 KRay/s
    6x Core i7-3960X Extreme HT    3300   Intel DX79SI                                                            X79                   Quad DDR3-1600        9-9-9-24 CR2   2638 KRay/s
    4x Core i7-5775C HT     3300   Gigabyte GA-Z97MX-Gaming 5                                              Z97 Int.              Dual DDR3-1600        11-11-11-28 CR1   2595 KRay/s
    4x Ryzen 5 2400G HT     3600   ASRock A320M Pro4                                                       A320                  Dual DDR4-2933        16-15-15-35 CR1   1963 KRay/s
    4x Core i7-3770K HT     3500   MSI Z77A-GD55                                                           Z77 Int.              Dual DDR3-1600        9-9-9-24 CR2   1918 KRay/s
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1   1817 KRay/s
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Quad DDR2-800R  6-6-6-18 CR1   1559 KRay/s
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1   1457 KRay/s
    8x FX-8350              4000   Asus M5A99X Evo R2.0                                                    AMD990X               Dual DDR3-1866        9-10-9-27 CR2   1388 KRay/s
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Hexa DDR3-1333        9-9-9-24 CR1   1379 KRay/s
    16x Atom C3958          2000   Supermicro A2SDi-H-TP4F                                                 Denverton             Dual DDR4-2400        17-17-17-39    1367 KRay/s
    8x FX-8150              3600   Asus M5A97                                                              AMD970                Dual DDR3-1866        9-10-9-27 CR2   1313 KRay/s
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15       1159 KRay/s
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Quad DDR2-800R  6-6-6-18 CR1   1039 KRay/s
    6x Phenom II X6 Black 1100T    3300   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1333  9-9-9-24 CR2   1037 KRay/s
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1    900 KRay/s
    6x FX-6100              3300   Asus Sabertooth 990FX                                                   AMD990FX              Dual DDR3-1866        9-10-9-27 CR2    874 KRay/s
    4x A12-9800             3800   Gigabyte GA-AB350M-Gaming 3                                             B350 Int.             Dual DDR4-2400        14-16-16-31 CR1    852 KRay/s
    4x A10-6800K            4100   Gigabyte GA-F2A85X-UP4                                                  A85X Int.             Dual DDR3-2133        9-11-10-27 CR2    737 KRay/s
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12        724 KRay/s
    4x A10-7850K            3700   Gigabyte GA-F2A88XM-D3H                                                 A88X Int.             Dual DDR3-2133        9-11-10-31 CR2    717 KRay/s
    4x A10-5800K            3800   Asus F2A55-M                                                            A55 Int.              Dual DDR3-1866        9-10-9-27 CR2    671 KRay/s
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Quad DDR2-667R  5-5-5-15 CR1    669 KRay/s
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2    626 KRay/s
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1    623 KRay/s
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1    623 KRay/s
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2    616 KRay/s
    4x Celeron J4105        1500   ASRock J4105-ITX                                                        GeminiLakeD Int.      Dual DDR4-2400        17-17-17-39     539 KRay/s
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15        534 KRay/s
    3x Athlon II X3 450     3200   Asus M5A78L-M LX3                                                       AMD760G               DDR3-1607 SDRAM       11-11-11-28 CR2    501 KRay/s
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15        466 KRay/s
    8x Atom C2750           2400   Supermicro A1SAi-2750F                                                  Avoton                Dual DDR3-1600        11-11-11-28 CR1    459 KRay/s
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2    452 KRay/s
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1    443 KRay/s
    4x Athlon 5350          2050   ASRock AM1B-ITX                                                         Yangtze Int.          DDR3-1600 SDRAM       11-11-11-28 CR2    435 KRay/s
    4x Celeron J3455        1500   ASRock J3455B-ITX                                                       ApolloLakeD Int.      Dual DDR3-1866        11-11-11-32 CR1    428 KRay/s
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2    285 KRay/s
    4x Celeron J1900        2000   Gigabyte GA-J1900N-D3V                                                  BayTrailD Int.        Dual DDR3-1333        9-9-9-24 CR1    210 KRay/s
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11        205 KRay/s
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7       197 KRay/s
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Quad DDR2-600R        5-5-5-15 CR1    193 KRay/s
    4x Celeron N3150        1600   ASRock N3150B-ITX                                                       Braswell Int.         Dual DDR3-1600        11-11-11-28 CR2    185 KRay/s
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1    176 KRay/s
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2    138 KRay/s
    Nano X2 L4350           1600   VIA EPIA-M900                                                           VX900H Int.           DDR3-1066 SDRAM       7-7-7-20 CR2    120 KRay/s
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15        109 KRay/s
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1     79 KRay/s
    Celeron 420             1600   Intel DQ965GF                                                           Q965 Int.             Dual DDR2-667         5-5-5-15         71 KRay/s
    2x Atom D525 HT         1800   Gigabyte GA-D525TUD                                                     NM10 Int.             DDR3-800 SDRAM        6-6-6-15 CR2     64 KRay/s
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11 CR2     62 KRay/s
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1      59 KRay/s
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2     56 KRay/s
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2     54 KRay/s
    2x Atom D2500           1866   Intel D2500CC                                                           NM10 Int.             DDR3-1066 SDRAM       7-7-7-20 CR2     46 KRay/s
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2     43 KRay/s
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12         28 KRay/s


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  AMD RS780/RS880 Chipset - Host Bridge
                  
      Offset 000:  22 10 00 96  06 00 30 22  00 00 00 06  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 88 83 
      Offset 030:  00 00 00 00  C4 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  08 9C 00 C0  C1 00 00 00  30 00 00 00  42 20 05 00 
      Offset 050:  43 10 88 83  08 40 00 90  08 10 05 00  08 00 00 00 
      Offset 060:  7D 00 00 00  00 86 64 3A  00 02 20 00  09 C0 86 81 
      Offset 070:  00 00 00 00  00 00 00 00  78 9D 0F 00  01 00 00 20 
      Offset 080:  00 00 00 00  10 00 00 03  20 3A 00 00  31 20 00 00 
      Offset 090:  00 00 00 D0  7F 00 00 00  00 00 00 00  08 F8 7C D0 
      Offset 0A0:  26 00 74 00  00 00 00 80  00 00 00 00  79 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 80  08 54 80 01  20 10 11 11  D0 00 00 00 
      Offset 0D0:  60 0B 75 1E  02 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  F0 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 80 80 00  08 00 00 E0  00 00 00 00 

    B00 D02 F00:  AMD RS780/RS880 Chipset - PCI Express Graphics Port 0
                  
      Offset 000:  22 10 03 96  07 01 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 01 01 00  D1 D1 00 20 
      Offset 020:  A0 FE A0 FE  01 D0 F1 DF  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 01 1B 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  20 80 00 00 
      Offset 060:  10 08 00 00  02 0D 30 00  40 00 81 F0  80 25 14 00 
      Offset 070:  00 00 48 01  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  42 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  43 10 88 83  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D04 F00:  AMD RS780/RS880 Chipset - PCI Express Port 0
                  
      Offset 000:  22 10 04 96  07 01 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 02 02 00  E1 E1 00 20 
      Offset 020:  B0 FE B0 FE  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  10 01 07 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  20 80 00 00 
      Offset 060:  10 08 00 00  12 0C 30 01  40 00 11 70  80 0C 24 00 
      Offset 070:  00 00 48 01  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  42 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  43 10 88 83  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D11 F00:  ATI SB750 - SATA Controller
                  
      Offset 000:  02 10 90 43  07 01 30 02  00 8F 01 01  10 40 00 00 
      Offset 010:  01 C0 00 00  01 B0 00 00  01 A0 00 00  01 90 00 00 
      Offset 020:  01 80 00 00  00 FC 9F FE  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  16 01 00 00 
      Offset 040:  10 00 00 00  01 00 10 00  C0 BF 00 00  00 00 00 00 
      Offset 050:  05 70 84 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  01 70 22 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  12 00 10 00  0F 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  06 00 00 2C  F6 A0 B4 01  F5 A0 B4 01 
      Offset 090:  F4 A0 B4 01  F4 A0 B4 01  F6 A0 B4 01  F7 A0 B4 01 
      Offset 0A0:  D8 A0 F8 A0  F7 A0 F7 A0  B8 A0 F7 A0  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 20 00 00 
      Offset 0E0:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F00:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 97 43  06 01 A0 02  00 10 03 0C  10 40 80 00 
      Offset 010:  00 E0 9F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  80 03 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 03 F6  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F01:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 98 43  16 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 D0 9F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F02:  ATI SB750 - EHCI USB 2.0 Controller
                  
      Offset 000:  02 10 96 43  06 01 B0 02  00 20 03 0C  10 40 00 00 
      Offset 010:  00 F8 9F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  11 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  D8 01 9E 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 00  00 20 00 C0  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F00:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 97 43  06 01 A0 02  00 10 03 0C  10 40 80 00 
      Offset 010:  00 C0 9F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  80 03 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 03 F6  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F01:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 98 43  16 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 B0 9F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F02:  ATI SB750 - EHCI USB 2.0 Controller
                  
      Offset 000:  02 10 96 43  06 01 B0 02  00 20 03 0C  10 40 00 00 
      Offset 010:  00 F4 9F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  D8 01 9E 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 00  00 20 00 C0  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F00:  ATI SB750 - SMBus Controller
                  
      Offset 000:  02 10 85 43  03 04 30 D2  3C 00 05 0C  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  B0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  44 EB 00 FD  00 00 00 00  0F FF 00 00  00 00 00 C0 
      Offset 050:  F0 01 F0 0C  F0 0F F0 0F  21 0B F0 C3  80 00 10 00 
      Offset 060:  01 00 A4 20  9F FC 9E 03  FF 90 00 00  20 00 00 00 
      Offset 070:  00 00 00 00  08 00 C0 FE  FF 6E 00 00  00 00 F0 06 
      Offset 080:  F0 0A F0 7E  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  01 0B 00 00  F9 CE FF 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 FF FF  00 00 F0 09  00 FF 08 02  06 59 20 18 
      Offset 0B0:  08 00 02 A8  00 00 D0 FE  00 00 00 00  F0 0F 08 1A 
      Offset 0C0:  FF FF FF FF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 01 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  20 99 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  D8 0C 00 00  00 00 44 00  00 00 00 00  02 00 10 00 

    B00 D14 F01:  ATI SB750 - IDE Controller
                  
      Offset 000:  02 10 9C 43  05 00 30 02  00 8A 01 01  00 00 00 00 
      Offset 010:  01 00 00 00  01 00 00 00  01 00 00 00  01 00 00 00 
      Offset 020:  01 FF 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  70 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  99 99 99 99  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 40 26  10 2C 01 07  01 00 00 00  FF FF 0F 00 
      Offset 070:  05 00 02 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F02:  ATI SB750 - High Definition Audio Controller
                  
      Offset 000:  02 10 83 43  06 00 10 04  00 00 03 04  10 40 00 00 
      Offset 010:  04 40 9F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 45 84 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  00 00 00 00  01 00 00 00  00 00 00 00  01 00 00 00 
      Offset 050:  01 00 42 C8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  05 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F03:  ATI SB750 - PCI-LPC Bridge
                  
      Offset 000:  02 10 9D 43  0F 00 20 02  00 00 01 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  04 00 00 00  55 C0 03 FF  17 FF 40 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  30 02 00 00  0E 00 0F 00  A0 FF FF FF 
      Offset 070:  67 45 23 00  00 00 00 00  14 00 00 00  05 0B 00 00 
      Offset 080:  08 00 03 A8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 08  01 00 00 00 
      Offset 0A0:  02 00 C1 FE  2F 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 E9  F2 FF 00 00 
      Offset 0C0:  00 00 00 00  00 00 08 00  F7 FF FF FD  00 00 00 78 
      Offset 0D0:  00 FF FF 00  00 00 00 FF  FF FF FF 00  00 00 00 0C 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F04:  ATI SB750 - PCI-PCI Bridge
                  
      Offset 000:  02 10 84 43  07 05 A0 02  00 01 04 06  00 40 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 03 03 40  F0 00 80 22 
      Offset 020:  F0 FF 00 00  F0 FF 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 07 00 
      Offset 040:  26 00 04 FF  00 00 00 00  0C 0F 3C D1  00 01 00 00 
      Offset 050:  01 00 00 00  08 00 03 A8  00 00 00 00  85 00 FF FF 
      Offset 060:  CA 0E 17 00  BA D8 10 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  01 00 02 06 
      Offset 0E0:  00 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F05:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 99 43  06 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 A0 9F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 03 00 00 
      Offset 040:  80 01 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 1F F6  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F00:  AMD K10 - HyperTransport Technology Configuration
                  
      Offset 000:  22 10 00 12  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  80 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 02 04 00  01 02 04 00  01 02 04 00  01 02 04 00 
      Offset 050:  01 02 04 00  01 02 04 00  01 02 04 00  01 02 04 00 
      Offset 060:  00 00 02 00  E0 00 00 00  20 A8 4F 00  10 FE 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  08 00 01 21  20 30 11 11  60 0B F5 8F  13 00 00 00 
      Offset 090:  CF 02 85 80  00 00 02 00  07 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F01:  AMD K10 - Address Map
                  
      Offset 000:  22 10 01 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  03 00 00 00  00 00 2F 02  00 00 00 00  01 00 00 00 
      Offset 050:  00 00 00 00  02 00 00 00  00 00 00 00  03 00 00 00 
      Offset 060:  00 00 00 00  04 00 00 00  00 00 00 00  05 00 00 00 
      Offset 070:  00 00 00 00  06 00 00 00  00 00 00 00  07 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  03 0A 00 00  00 0B 00 00  03 00 D0 00  00 FF DF 00 
      Offset 0B0:  03 00 E0 00  80 FF EF 00  03 00 F0 00  00 DF FF 00 
      Offset 0C0:  13 10 00 00  00 F0 FF 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  03 00 00 1F  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  03 30 00 D0  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F02:  AMD K10 - DRAM Controller
                  
      Offset 000:  22 10 02 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 00 00 00  09 01 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  E0 3E F8 01  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  06 00 88 0D  38 00 11 18 
      Offset 080:  0A 00 00 00  E4 00 34 00  67 DB 5C 00  66 7A 42 00 
      Offset 090:  00 00 01 00  0E 09 58 5F  14 00 00 80  1C 00 03 00 
      Offset 0A0:  00 02 00 00  00 00 00 00  40 00 00 00  00 00 00 00 
      Offset 0B0:  4F F4 8B DA  A7 00 00 00  FB FD 87 1F  FF 03 00 E0 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  FF 9F 00 04  F0 FF 1F F8  FF FF FF FF  FF 7F F8 FF 
      Offset 0E0:  FF FF 0F FC  FF F7 3F FC  00 FC FF FF  FF 5F 07 E0 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 100:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 110:  00 05 00 00  00 00 00 00  24 A4 40 04  C0 0F E0 2C 
      Offset 120:  FF 03 FF 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 130:  FF 1F 00 FF  FF FF A0 FF  FF FF FF F9  3F 80 00 BE 
      Offset 140:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 150:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 160:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 170:  00 00 00 00  00 00 00 00  06 00 C0 0A  00 00 00 00 
      Offset 180:  00 00 00 00  04 00 00 00  00 00 00 FF  00 00 00 00 
      Offset 190:  00 00 01 08  00 41 08 00  2A 00 00 80  00 00 00 00 
      Offset 1A0:  00 02 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1B0:  01 01 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F03:  AMD K10 - Miscellaneous Control
                  
      Offset 000:  22 10 03 12  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  F0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  FF FF FF 3F  5C 00 B0 4A  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 10 12 00  00 00 00 00 
      Offset 060:  00 00 00 00  05 62 3F 34  00 00 00 30  51 80 01 60 
      Offset 070:  51 11 32 60  01 01 98 00  14 0C 20 00  0D 08 07 00 
      Offset 080:  81 E6 0B E6  E6 41 E6 01  08 00 00 00  00 00 58 42 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 08 15 B0  EF 0F 48 19  0C 05 04 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  26 0F 81 C8  16 17 28 03  28 53 27 00 
      Offset 0E0:  00 00 00 00  30 18 C0 1C  59 6F 07 00  00 00 00 00 
      Offset 0F0:  0F 00 10 00  00 00 00 00  00 00 00 00  53 0F 10 00 

    B00 D18 F04:  AMD K10 - Link Control
                  
      Offset 000:  22 10 04 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B01 D00 F00:  AMD Radeon R7 240 (Oland) Video Adapter
                  
      Offset 000:  02 10 17 66  07 05 10 00  C7 00 00 03  10 00 80 00 
      Offset 010:  0C 00 00 D0  00 00 00 00  04 00 AC FE  00 00 00 00 
      Offset 020:  01 D0 00 00  00 00 00 00  00 00 00 00  87 17 00 20 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  09 50 08 00  87 17 00 20 
      Offset 050:  01 58 03 76  00 00 00 00  10 A0 12 00  A1 8F 2C 01 
      Offset 060:  10 29 09 00  82 0C 40 00  40 00 81 10  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  06 00 00 00  02 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 00 81 00  0C 70 E0 FE  00 00 00 00  B0 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B01 D00 F01:  AMD Cape Verde/Pitcairn/Curacao/Heathrow/Chelsea/Venus - High Definition Audio Controller
                  
      Offset 000:  02 10 B0 AA  06 01 10 00  00 00 03 04  10 00 80 00 
      Offset 010:  04 C0 A9 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  87 17 B0 AA 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  09 50 08 00  87 17 B0 AA 
      Offset 050:  01 58 03 06  00 00 00 00  10 A0 12 00  A1 8F 2C 01 
      Offset 060:  10 29 09 00  82 0C 40 00  40 00 81 10  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  06 00 00 00  00 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F00:  Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller
                  
      Offset 000:  69 19 A1 10  07 01 10 40  10 00 00 02  10 00 00 00 
      Offset 010:  04 00 BC FE  00 00 00 00  01 EC 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 87 85 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  01 58 C3 F9  08 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  10 C0 01 00  C5 FF 64 00 
      Offset 060:  00 20 1A 00  11 FC 07 00  40 00 11 10  03 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  69 19 A1 10  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  05 D8 88 01  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  11 00 0F 00  00 20 00 00 
      Offset 0E0:  00 30 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    PCI-1002-9600:  ATI ClkConfig
                  
      Offset 00:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  01 00 04 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  42 00 00 00 
      Offset 60:  00 00 00 00  8B 8B 8B 8B  9F 10 03 00  80 00 00 00 
      Offset 70:  01 00 00 02  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  3F 5F C4 80 
      Offset 90:  FF 03 00 00  1F FF FE 6A  40 00 00 00  00 00 00 00 
      Offset A0:  60 60 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  FF FF 10 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  6C 7B 00 00  9D 00 00 00  00 00 00 00 
      Offset E0:  01 00 4D 07  0C 01 00 00  00 00 00 EC  03 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  30 CF 00 00  00 00 00 00 

    PCI-1002-9600:  ATI RS690/RD780/RD790/RS740/RS780/RX790/RS880 NBMCIND
                  
      Offset 00:  00AC0056 88148200 00030200 00000000 
      Offset 04:  08881018 0000BBBB 00000002 00000000 
      Offset 08:  10000A00 00000008 50505411 00100000 
      Offset 0C:  0F000000 00054064 0AAAA000 00000000 
      Offset 10:  00FF0000 00000000 00000000 00000000 
      Offset 14:  00000000 08CC8888 000E2403 D1E01094 
      Offset 18:  01FFFF0F 00000000 00000000 00000000 
      Offset 1C:  00000000 0000FFFF 0000FFFF 0000FFFF 
      Offset 20:  0000FFFF 0000FFFF 0000FFFF 11111111 
      Offset 24:  00000010 00000010 00000000 00000000 
      Offset 28:  00000000 12280000 00070440 0710FFF0 
      Offset 2C:  00010908 00000000 00000000 00000000 
      Offset 30:  00000001 02000001 04000000 04000000 
      Offset 34:  04000000 04000000 04000000 04000000 
      Offset 38:  00F83FE0 1FF83FE0 1FF83FE0 1FF83FE0 
      Offset 3C:  000000BB 00000001 02000001 04000000 
      Offset 40:  04000000 04000000 04000000 04000000 
      Offset 44:  04000000 00F83FE0 1FF83FE0 1FF83FE0 
      Offset 48:  1FF83FE0 000000BB 00020007 00000000 
      Offset 4C:  00000000 00000000 00000000 00000000 
      Offset 50:  00000000 00000000 00000000 00000000 
      Offset 54:  00000000 00000000 00000000 00000000 
      Offset 58:  00000000 00000000 00000000 00000000 
      Offset 5C:  00000400 00000000 00000000 00000000 
      Offset 60:  00000000 00000000 00000000 00000000 
      Offset 64:  00000000 00000000 00000000 00000000 
      Offset 68:  00000000 00000000 00000000 00000000 
      Offset 6C:  00000000 00000000 00000000 00000000 
      Offset 70:  00000000 00000000 00000000 00000000 
      Offset 74:  00000000 00000000 00000000 00000000 
      Offset 78:  00000000 00000000 00000000 00000000 
      Offset 7C:  00000000 00000000 00000000 00000000 
      Offset 80:  00000000 00000000 00000000 00000000 
      Offset 84:  00000000 00000000 00000000 00000000 
      Offset 88:  00000000 00000000 00000000 00000000 
      Offset 8C:  00000000 00000000 00000000 00000000 
      Offset 90:  00000000 00000000 00000000 00000000 
      Offset 94:  00000000 00000000 00000000 00000000 
      Offset 98:  00000000 00000000 00000000 00000000 
      Offset 9C:  00000000 00000000 00000000 00000000 
      Offset A0:  00F00000 01F10000 74F20000 4AF30000 
      Offset A4:  22224851 00000000 00000000 00000000 
      Offset A8:  68488834 10282018 23212421 21482286 
      Offset AC:  00000000 00000000 00000000 00040000 
      Offset B0:  48800000 33330223 00000202 00000000 
      Offset B4:  05000A00 0CBDDDDC 00000033 00000044 
      Offset B8:  BBBBBBBB BBBBBBBB 55555555 BBBBBBBB 
      Offset BC:  BBBBBBBB 00000000 00000000 00000000 
      Offset C0:  00000000 00000000 00000000 80006B00 
      Offset C4:  04355554 00000000 00000000 00000000 
      Offset C8:  23F00000 01F10000 00F20000 05F30000 
      Offset CC:  68488834 10282018 33212421 21482286 
      Offset D0:  00000202 00000000 00000033 00000044 
      Offset D4:  00000000 00000000 00000000 00000000 
      Offset D8:  00A000A0 00A000A0 00000000 00000000 
      Offset DC:  00000000 00000000 00000000 00000000 
      Offset E0:  00380038 00380038 00000000 00000000 
      Offset E4:  00000000 00000000 00000000 00000000 
      Offset E8:  00380038 00380038 00000000 00000000 
      Offset EC:  00000000 00000000 00000000 00000000 
      Offset F0:  00000000 00000000 00000000 00000000 
      Offset F4:  00000000 00000000 00000000 00000000 
      Offset F8:  00000000 00000000 00000000 00000000 
      Offset FC:  00000000 00000000 00000000 00000000 
      Offset 100:  00AC0056 88148200 00030200 00000000 
      Offset 104:  08881018 0000BBBB 00000002 00000000 
      Offset 108:  10000A00 00000008 50505411 00100000 
      Offset 10C:  0F000000 00054064 0AAAA000 00000000 
      Offset 110:  00FF0000 00000000 00000000 00000000 
      Offset 114:  00000000 08CC8888 000E2403 D1E01094 
      Offset 118:  01FFFF0F 00000000 00000000 00000000 
      Offset 11C:  00000000 0000FFFF 0000FFFF 0000FFFF 
      Offset 120:  0000FFFF 0000FFFF 0000FFFF 11111111 
      Offset 124:  00000010 00000010 00000000 00000000 
      Offset 128:  00000000 12280000 00070440 0710FFF0 
      Offset 12C:  00010908 00000000 00000000 00000000 
      Offset 130:  00000001 02000001 04000000 04000000 
      Offset 134:  04000000 04000000 04000000 04000000 
      Offset 138:  00F83FE0 1FF83FE0 1FF83FE0 1FF83FE0 
      Offset 13C:  000000BB 00000001 02000001 04000000 
      Offset 140:  04000000 04000000 04000000 04000000 
      Offset 144:  04000000 00F83FE0 1FF83FE0 1FF83FE0 
      Offset 148:  1FF83FE0 000000BB 00020007 00000000 
      Offset 14C:  00000000 00000000 00000000 00000000 
      Offset 150:  00000000 00000000 00000000 00000000 
      Offset 154:  00000000 00000000 00000000 00000000 
      Offset 158:  00000000 00000000 00000000 00000000 
      Offset 15C:  00000400 00000000 00000000 00000000 
      Offset 160:  00000000 00000000 00000000 00000000 
      Offset 164:  00000000 00000000 00000000 00000000 
      Offset 168:  00000000 00000000 00000000 00000000 
      Offset 16C:  00000000 00000000 00000000 00000000 
      Offset 170:  00000000 00000000 00000000 00000000 
      Offset 174:  00000000 00000000 00000000 00000000 
      Offset 178:  00000000 00000000 00000000 00000000 
      Offset 17C:  00000000 00000000 00000000 00000000 
      Offset 180:  00000000 00000000 00000000 00000000 
      Offset 184:  00000000 00000000 00000000 00000000 
      Offset 188:  00000000 00000000 00000000 00000000 
      Offset 18C:  00000000 00000000 00000000 00000000 
      Offset 190:  00000000 00000000 00000000 00000000 
      Offset 194:  00000000 00000000 00000000 00000000 
      Offset 198:  00000000 00000000 00000000 00000000 
      Offset 19C:  00000000 00000000 00000000 00000000 
      Offset 1A0:  00F00000 01F10000 74F20000 4AF30000 
      Offset 1A4:  22224851 00000000 00000000 00000000 
      Offset 1A8:  68488834 10282018 23212421 21482286 
      Offset 1AC:  00000000 00000000 00000000 00040000 
      Offset 1B0:  48800000 33330223 00000202 00000000 
      Offset 1B4:  05000A00 0CBDDDDC 00000033 00000044 
      Offset 1B8:  BBBBBBBB BBBBBBBB 55555555 BBBBBBBB 
      Offset 1BC:  BBBBBBBB 00000000 00000000 00000000 
      Offset 1C0:  00000000 00000000 00000000 80006B00 
      Offset 1C4:  04355554 00000000 00000000 00000000 
      Offset 1C8:  23F00000 01F10000 00F20000 05F30000 
      Offset 1CC:  68488834 10282018 33212421 21482286 
      Offset 1D0:  00000202 00000000 00000033 00000044 
      Offset 1D4:  00000000 00000000 00000000 00000000 
      Offset 1D8:  00A000A0 00A000A0 00000000 00000000 
      Offset 1DC:  00000000 00000000 00000000 00000000 
      Offset 1E0:  00380038 00380038 00000000 00000000 
      Offset 1E4:  00000000 00000000 00000000 00000000 
      Offset 1E8:  00380038 00380038 00000000 00000000 
      Offset 1EC:  00000000 00000000 00000000 00000000 
      Offset 1F0:  00000000 00000000 00000000 00000000 
      Offset 1F4:  00000000 00000000 00000000 00000000 
      Offset 1F8:  00000000 00000000 00000000 00000000 
      Offset 1FC:  00000000 00000000 00000000 00000000 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U.......................0.....IBM].............. 761295520......
    C000:0040  ................07/14/16 02:38..8..................`.@...Rb.....
    C000:0080  ./...............>x...X@,...... .........@...0WX...............
    C000:00C0  ........................113-H240A-2TSX-100-06.OLAND.PCI_EXPRESS.
    C000:0100  DDR3...C92401-Oland LE 2GB DDR3 128Mx16                         
    C000:0140                    ..... ...(C) 1988-2010, Advanced Micro Devices
    C000:0180  , Inc..ATOMBIOSBK-AMD VER015.049.000.013.000000.H2402G06.W80.127
    C000:01C0  0211 .346527  .        .XFX_OLAND_C92401_D3_2GB_4VID131204HJE\co
    C000:0200  nfig.h....$...ATOM......U............ 0...B.....PCIR...f........
    C000:0240  ..1.....AMD ATOMBIOS.>F.s...........Z..c...~..AR...............
    C000:0280  .....V.......MP. .^..fPfQfRfSfUfVfW.......... ..2..u....f_f^f]f[
    C000:02C0  fZfYfX.....3..12... ....f.......3..b........[..s..EP. u.. ...t..
    C000:0300  I..8]....].......1..f.......fP.....3..fXt.. f...........3f_f^f]
    C000:0340  f[fZfYfX.........>...u.............f....e.....@.....B...........
    C000:0380  ..|..e..~......i.........`.............`..`.'`...PMID...M.......
    C000:03C0  ...........o2f....6.....2.X.u..:&,.u..G.....Ou...H...YO......2..


--------[ Debug - Unknown ]---------------------------------------------------------------------------------------------

    SSD             WD5001AALS-00LWTA0


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
