--------[ AIDA64 Extreme Edition ]--------------------------------------------------------------------------------------

                                                AIDA64 v1.85.1600/ru
                                        2.7.380-x64
                                      http://www.aida64.com/
                                              
                                             APARRATUS-
                                             Aparratus
                                   Microsoft Windows 7 Ultimate 6.1.7600 (Win7 RTM)
                                                  2011-11-02
                                                 23:02


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI x64-based PC
                                     Microsoft Windows 7 Ultimate
                                       -
      Internet Explorer                                 8.0.7600.16385 (IE 8.0 - Windows 7)
      DirectX                                           DirectX 11.0
                                           APARRATUS-
                                         Aparratus
                                              Aparratus-
       /                                       2011-11-02 / 23:02

     :
                                                   QuadCore Intel Core 2 Quad Q9550, 2833 MHz (8.5 x 333)
                                          Asus Maximus II Formula  (2 PCI, 3 PCI-E x1, 2 PCI-E x16, 4 DDR2 DIMM, Audio, Dual Gigabit LAN, IEEE-1394)
                                    Intel Eaglelake P45
                                         8192   (DDR2-800 DDR2 SDRAM)
      DIMM1: GeIL CL5-5-5DDR21066 5                     2  DDR2-800 DDR2 SDRAM  (5-5-5-15 @ 400 )  (4-5-5-13 @ 333 )  (3-4-4-10 @ 266 )
      DIMM2: GeIL CL5-5-5DDR21066 5                     2  DDR2-800 DDR2 SDRAM  (5-5-5-15 @ 400 )  (4-5-5-13 @ 333 )  (3-4-4-10 @ 266 )
      DIMM3: GeIL CL5-5-5DDR21066 5                     2  DDR2-800 DDR2 SDRAM  (5-5-5-15 @ 400 )  (4-5-5-13 @ 333 )  (3-4-4-10 @ 266 )
      DIMM4: GeIL CL5-5-5DDR21066 5                     2  DDR2-800 DDR2 SDRAM  (5-5-5-15 @ 400 )  (4-5-5-13 @ 333 )  (3-4-4-10 @ 266 )
       BIOS                                          AMI (04/15/10)

    :
                                            NVIDIA GeForce GTX 580  (1536 )
                                            NVIDIA GeForce GTX 580  (1536 )
      3D-                                    nVIDIA GeForce GTX 580
                                                 ViewSonic VX2240w  [22" LCD]  (QRB074220815)

    :
                                         Analog Devices AD2000B @ Intel 82801JB ICH10 - High Definition Audio Controller
                                         nVIDIA HDMI/DP @ nVIDIA GF110 - High Definition Audio Controller
                                         nVIDIA HDMI/DP @ nVIDIA GF110 - High Definition Audio Controller
                                         nVIDIA HDMI/DP @ nVIDIA GF110 - High Definition Audio Controller
                                         nVIDIA HDMI/DP @ nVIDIA GF110 - High Definition Audio Controller

     :
       IDE                                    Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
       IDE                                    Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
       IDE                                       PCI IDE
                                AUWTM4QJ IDE Controller
      -                                 
                                      WDC WD5000AAKS-22A7B2 ATA Device  (465 , IDE)
                                    EDQPEB CX2J4HYRKP2B SCSI CdRom Device
      SMART-                         OK

    :
      C: (NTFS)                                         51239  (2764  )
      D: (NTFS)                                         415.7  (152.9  )
                                              465.8  (155.6  )

    :
                                               HID
                                                PS/2
                                                    HID- 
                                                    HID- 

    :
        IP                                192.168.1.2
        MAC                                  
                                          Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller  (192.168.1.2)
                                          Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
                                          Realtek RTL8139/810x Family Fast Ethernet  
                                          TAP-Win32 Adapter V9 (Tunngle)

     :
                                                 Fax
                                                 HP Officejet 4300 Series
                                                 Microsoft XPS Document Writer
       FireWire                               VIA VT6308 Fire IIM IEEE1394 Host Controller (PHY: VIA VT6307)
       USB1                                   Intel 82801JB ICH10 - USB Universal Host Controller
       USB1                                   Intel 82801JB ICH10 - USB Universal Host Controller
       USB1                                   Intel 82801JB ICH10 - USB Universal Host Controller
       USB1                                   Intel 82801JB ICH10 - USB Universal Host Controller
       USB1                                   Intel 82801JB ICH10 - USB Universal Host Controller
       USB1                                   Intel 82801JB ICH10 - USB Universal Host Controller
       USB2                                   Intel 82801JB ICH10 - USB2 Enhanced Host Controller
       USB2                                   Intel 82801JB ICH10 - USB2 Enhanced Host Controller
      USB-                                    DeathAdder Mouse

    DMI:
      DMI  BIOS                                American Megatrends Inc.
      DMI  BIOS                                   2302
      DMI                           System manufacturer
      DMI                                        Maximus II Formula
      DMI                                System Version
      DMI                         System Serial Number
      DMI  UUID                                4045001E-8C00016A-47990022-1569A6E6
      DMI                    ASUSTeK Computer INC.
      DMI                                 Maximus II Formula
      DMI                           Rev 1.xx
      DMI                    MS1C87BX3100797
      DMI                             Chassis Manufacture
      DMI                                    Chassis Version
      DMI                             Chassis Serial Number
      DMI Asset-                                Asset-1234567890
      DMI                                       Desktop Case
      DMI  /                 4 / 0


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 APARRATUS-
      DNS               Aparratus-
      DNS              
      DNS              Aparratus-
     NetBIOS                 APARRATUS-
      DNS               Aparratus-
      DNS              
      DNS              Aparratus-


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           American Megatrends Inc.
                                                  2302
                                             04/15/2010
                                                  2048 
                                   Floppy Disk, Hard Disk, CD-ROM, ATAPI ZIP, LS-120
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS
                                 DMI, APM, ACPI, ESCD, PnP
                                   ISA, PCI, USB

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                   http://www.aida64.com/bios-updates

  [  ]

     :
                                           System manufacturer
                                                 Maximus II Formula
                                                  System Version
                                           System Serial Number
      SKU#                                              To Be Filled By O.E.M.
                                               To Be Filled By O.E.M.
        ID                       4045001E-8C00016A-47990022-1569A6E6
                                           

  [   ]

      :
                                           ASUSTeK Computer INC.
                                                 Maximus II Formula
                                                  Rev 1.xx
                                           MS1C87BX3100797

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/Motherboards
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates
       BIOS                                   http://www.aida64.com/bios-updates

  [  ]

     :
                                           Chassis Manufacture
                                                  Chassis Version
                                           Chassis Serial Number
                                            Asset-1234567890
                                                
                                     
                               
                                  
                                   

  [   ]

      :
                                  64-bit ECC
                                         
                              1-Way
                                1-Way
                                DIMM
                   3.3V
                           2048 
                                           4

  [  / Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz ]

     :
                                           Intel
                                                  Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
                                           To Be Filled By O.E.M.
                                            To Be Filled By O.E.M.
                                          To Be Filled By O.E.M.
                                          333 
                                     3800 
                                          2833 
                                                     Central Processor
                                       1.2 V
                                                  
                                              LGA 775
      HTT / CMP                                         1 / 4

     :
                                                   Intel Corporation
                                     http://ark.intel.com/search.aspx?q=Intel Core 2 Quad Q9550
                                     http://www.aida64.com/driver-updates

  [ - / L1-Cache ]

     :
                                                     
                                                  
                                             Write-Back
                                         8-way Set-Associative
                                       128 
                                      128 
                                         Parity
                                              L1-Cache

  [ - / L2-Cache ]

     :
                                                     
                                                  
                                             Write-Back
                                       12288 
                                      12288 
                                         Single-bit ECC
                                              L2-Cache

  [ - / L3-Cache ]

     :
                                                     
                                                  
                                       0 
                                      0 
                                              L3-Cache

  [   / DIMM0 ]

      :
                                              DIMM0
                                                     DIMM
                                                19 ns
                                      2048 
                                         2048 

  [   / DIMM1 ]

      :
                                              DIMM1
                                                     DIMM
                                                19 ns
                                      2048 
                                         2048 

  [   / DIMM2 ]

      :
                                              DIMM2
                                                     DIMM
                                                19 ns
                                      2048 
                                         2048 

  [   / DIMM3 ]

      :
                                              DIMM3
                                                     DIMM
                                                19 ns
                                      2048 
                                         2048 

  [   / DIMM0 ]

      :
      -                                       DIMM
                                                     DDR
                                                     Synchronous
                                                  2048 
                                                1066 
                                             64 
                                            64 
                                              DIMM0
                                                    BANK0
                                           Manufacturer00
                                           SerNum00
                                            AssetTagNum0
                                          ModulePartNumber00

  [   / DIMM1 ]

      :
      -                                       DIMM
                                                     DDR
                                                     Synchronous
                                                  2048 
                                                1066 
                                             64 
                                            64 
                                              DIMM1
                                                    BANK1
                                           Manufacturer01
                                           SerNum01
                                            AssetTagNum1
                                          ModulePartNumber01

  [   / DIMM2 ]

      :
      -                                       DIMM
                                                     DDR
                                                     Synchronous
                                                  2048 
                                                1066 
                                             64 
                                            64 
                                              DIMM2
                                                    BANK2
                                           Manufacturer02
                                           SerNum02
                                            AssetTagNum2
                                          ModulePartNumber02

  [   / DIMM3 ]

      :
      -                                       DIMM
                                                     DDR
                                                     Synchronous
                                                  2048 
                                                1066 
                                             64 
                                            64 
                                              DIMM3
                                                    BANK3
                                           Manufacturer03
                                           SerNum03
                                            AssetTagNum3
                                          ModulePartNumber03

  [   / PCIEX16 ]

      :
                                       PCIEX16
                                                     PCI-E x1
                                           
                                        32-bit
                                                   

  [   / PCIEX1_1 ]

      :
                                       PCIEX1_1
                                                     PCI-X
                                           
                                        32-bit
                                                   

  [   / PCIEX1_2 ]

      :
                                       PCIEX1_2
                                                     PCI-E x1
                                           
                                        64-bit
                                                   

  [   / PCIEX16_2 ]

      :
                                       PCIEX16_2
                                                     PCI-X
                                           
                                        32-bit
                                                   

  [   / PCI_1 ]

      :
                                       PCI_1
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI_2 ]

      :
                                       PCI_2
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PS/2 Keyboard ]

      :
                                                Keyboard Port
                                   PS/2 Keyboard
                                    
                                      PS/2 Keyboard
                                       PS/2

  [   / USB12 ]

      :
                                                USB
                                   USB12
                                    
                                      USB12
                                       USB

  [   / USB34 ]

      :
                                                USB
                                   USB34
                                    
                                      USB34
                                       USB

  [   / USB34 ]

      :
                                                USB
                                   USB56
                                    
                                      USB34
                                       USB

  [   / USB34 ]

      :
                                                USB
                                   USB78
                                    
                                      USB34
                                       USB

  [   / USB34 ]

      :
                                                USB
                                   USB910
                                    
                                      USB34
                                       USB

  [   / GbE LAN ]

      :
                                                Network Port
                                   GbE LAN 1
                                    
                                      GbE LAN
                                       RJ-45

  [   / GbE LAN ]

      :
                                                Network Port
                                   GbE LAN 2
                                    
                                      GbE LAN
                                       RJ-45

  [   / AUDIO ]

      :
                                                Audio Port
                                   AUDIO
                                    
                                      AUDIO

  [   / Audio Line Out1 ]

      :
                                                Audio Port
                                   Audio Line Out1
                                    
                                      Audio Line Out1
                                       Mini-jack (headphones)

  [   / Audio Line Out2 ]

      :
                                                Audio Port
                                   Audio Line Out2
                                    
                                      Audio Line Out2
                                       Mini-jack (headphones)

  [   / Audio Line Out3 ]

      :
                                                Audio Port
                                   Audio Line Out3
                                    
                                      Audio Line Out3
                                       Mini-jack (headphones)

  [   / Audio Line Out4 ]

      :
                                                Audio Port
                                   Audio Line Out4
                                    
                                      Audio Line Out4
                                       Mini-jack (headphones)

  [   / Audio Line Out5 ]

      :
                                                Audio Port
                                   Audio Line Out5
                                    
                                      Audio Line Out5
                                       Mini-jack (headphones)

  [   / Audio Line Out6 ]

      :
                                                Audio Port
                                   Audio Line Out6
                                    
                                      Audio Line Out6
                                       Mini-jack (headphones)

  [   / SPDIF_OUT ]

      :
                                                Audio Port
                                   SPDIF_OUT
                                    
                                      SPDIF_OUT
                                       On-Board Sound Input from CD-ROM

  [   / IE1394_1 ]

      :
                                                FireWire (IEEE P1394)
                                   IE1394_1
                                    
                                      IE1394_1
                                       1394

  [   / IE1394_2 ]

      :
                                                FireWire (IEEE P1394)
                                   IE1394_2
                                    
                                      IE1394_2
                                       1394

  [   / SATA1 ]

      :
                                                SATA
                                   SATA1
                                    SATA/SAS Plug Receptacle
                                       

  [   / SATA2 ]

      :
                                                SATA
                                   SATA2
                                    SATA/SAS Plug Receptacle
                                       

  [   / SATA3 ]

      :
                                                SATA
                                   SATA3
                                    SATA/SAS Plug Receptacle
                                       

  [   / SATA4 ]

      :
                                                SATA
                                   SATA4
                                    SATA/SAS Plug Receptacle
                                       

  [   / SATA5 ]

      :
                                                SATA
                                   SATA5
                                    SATA/SAS Plug Receptacle
                                       

  [   / SATA6 ]

      :
                                                SATA
                                   SATA6
                                    SATA/SAS Plug Receptacle
                                       

  [   / PRI_EIDE ]

      :
                                                SATA
                                   PRI_EIDE
                                    SATA/SAS Plug Receptacle
                                       

  [   / SATAE1 ]

      :
                                                SATA
                                   SATAE1
                                    SATA/SAS Plug Receptacle
                                       

  [   / FLOPPY ]

      :
                                   FLOPPY
                                    On-Board Floppy
                                       

  [   / CD ]

      :
                                                Audio Port
                                   CD
                                    On-Board Sound Input from CD-ROM
                                       

  [   / AAFP ]

      :
                                                Audio Port
                                   AAFP
                                    Mini-jack (headphones)
                                       

  [   / FP_AUDIO ]

      :
                                                Audio Port
                                   FP_AUDIO
                                    On-Board Sound Input from CD-ROM
                                       

  [   / CPU_FAN ]

      :
                                   CPU_FAN
                                       

  [   / PWR_FAN ]

      :
                                   PWR_FAN
                                       

  [   / Onboard Ethernet ]

      :
                                                Onboard Ethernet
                                                     Ethernet
                                                  

  [  ]

    :
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      System Configuration Option                       To Be Filled By O.E.M.


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   QuadCore Intel Core 2 Quad Q9550
                                             Yorkfield
                                              C1
      Engineering Sample                                
        CPUID                                      Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
       CPUID                                      00010677h
      CPU VID                                           1.1500 V

     :
                                               2003.7 MHz  (: 2833 MHz)
                                             6x
      CPU FSB                                           334.0 MHz  (: 333 MHz)
                                              534.3 MHz
       DRAM:FSB                              16:10

     :
       L1                                        32  per core
       L1                                      32  per core
       L2                                            2x 6   (On-Die, ECC, ASC, Full-Speed)

      :
      ID                                  65-2302-000001-00101111-041510-Eaglelake$A1007001_BIOS DATE: 04/15/10 17:15:35 VER: 08.00.14
                                          Asus Maximus II Formula  (2 PCI, 3 PCI-E x1, 2 PCI-E x16, 4 DDR2 DIMM, Audio, Dual Gigabit LAN, IEEE-1394)

       ():
                                    Intel Eaglelake P45
                                          5-5-5-15  (CL-RCD-RP-RAS)
      Command Rate (CR)                                 2T
      DIMM1: GeIL CL5-5-5DDR21066 5                     2  DDR2-800 DDR2 SDRAM  (5-5-5-15 @ 400 )  (4-5-5-13 @ 333 )  (3-4-4-10 @ 266 )
      DIMM2: GeIL CL5-5-5DDR21066 5                     2  DDR2-800 DDR2 SDRAM  (5-5-5-15 @ 400 )  (4-5-5-13 @ 333 )  (3-4-4-10 @ 266 )
      DIMM3: GeIL CL5-5-5DDR21066 5                     2  DDR2-800 DDR2 SDRAM  (5-5-5-15 @ 400 )  (4-5-5-13 @ 333 )  (3-4-4-10 @ 266 )
      DIMM4: GeIL CL5-5-5DDR21066 5                     2  DDR2-800 DDR2 SDRAM  (5-5-5-15 @ 400 )  (4-5-5-13 @ 333 )  (3-4-4-10 @ 266 )

     BIOS:
       BIOS                                  04/15/10
       BIOS                            02/10/11
      DMI  BIOS                                   2302

      :
                                            Zotac GeForce GTX 580
                                       GF110  (PCI Express 2.0 x16 10DE / 1080, Rev A1)
        (Geometric Domain)                     405   (: 772 MHz)
        (Shader Domain)                        810   (: 1544 MHz)
                                           162   (: 1002 MHz)


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                         
                              
                          


--------[   ]----------------------------------------------------------------------------------------------

    Centrino (Carmel)  :
      : Intel Pentium M (Banias/Dothan)                 (Intel Core 2 Quad Q9550)
      : Intel i855GM/PM                             (Intel Eaglelake P45)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Sonoma)  :
      : Intel Pentium M (Dothan)                        (Intel Core 2 Quad Q9550)
      : Intel i915GM/PM                             (Intel Eaglelake P45)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Napa)  :
      : Intel Core (Yonah) / Core 2 (Merom)             (Intel Core 2 Quad Q9550)
      : Intel i945GM/PM                             (Intel Eaglelake P45)
      WLAN: Intel PRO/Wireless 3945                     
      : Centrino-                     

    Centrino (Santa Rosa)  :
      : Intel Core 2 (Merom/Penryn)                     (Intel Core 2 Quad Q9550)
      : Intel GM965/PM965                           (Intel Eaglelake P45)
      WLAN: Intel Wireless WiFi Link 4965               
      : Centrino-                     

    Centrino 2 (Montevina)  :
      : Intel Core 2 (Penryn)                           (Intel Core 2 Quad Q9550)
      : Intel GM45/GM47/GS45/PM45                   (Intel Eaglelake P45)
      WLAN: Intel WiFi Link 5000 Series                 
      : Centrino 2-                   

    Centrino (Calpella)  :
      : Intel Core i3/i5/i7 (Arrandale/Clarksfield)     (Intel Core 2 Quad Q9550)
      : Intel HM55/HM57/PM55                        (Intel Eaglelake P45)
      WLAN: Intel WiFi Link 1000/WiMAX 6000 Series      
      : Centrino-                     


--------[  ]-----------------------------------------------------------------------------------------------------

     :
                                              Winbond W83667HG  (ISA 290h)
                                            Diode, CHiL CHL8266  (NV-Diode, 46h)
                                          Asus Maximus II Series
                               

    :
                                          44 C  (111 F)
                                                      30 C  (86 F)
       1 /  1                                     50 C  (122 F)
       1 /  2                                     46 C  (115 F)
       1 /  3                                     46 C  (115 F)
       1 /  4                                     45 C  (113 F)
                                            51 C  (124 F)
                                               55 C  (131 F)
      PWM                                               38 C  (100 F)
                                                  47 C  (117 F)
      WDC WD5000AAKS-22A7B2                             43 C  (109 F)

    :
                                                      2163 RPM
       3                                      1172 RPM
                                    1440 RPM  (41%)

    :
                                                  1.208 V
      +3.3 V                                            3.296 V
      +5 V                                              4.896 V
      +12 V                                             11.984 V
      +5 V                                        5.164 V
      CPU VTT                                           1.118 V
      CPU PLL                                           1.535 V
        +1.1 V                              1.124 V
        +1.1 V                                 1.124 V
        +1.5 V                                 1.501 V
      DIMM                                              2.090 V
      DIMM VTT                                          1.045 V
                                                  0.963 V
      GPU +12V                                          12.031 V
      GPU VRM                                           0.955 V

     :
                                                      19.97 A
      GPU VRM                                           11.00 A

     :
                                                      24.13 W
      GPU VRM                                           10.50 W
      Debug Info F                                      FF 27 FF / FF FF
      Debug Info T                                      45 30 27
      Debug Info V                                      8C D6 D0 CE CC FF 99 (03)
      Debug Info I                                      C1 A513


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   QuadCore Intel Core 2 Quad Q9550, 2833 MHz (8.5 x 333)
                                             Yorkfield
                                              C1
                                        x86, x86-64, MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1
                                         2833 
      ./.                             6.0x / 8.5x
      Engineering Sample                                
       L1                                        32  per core
       L1                                      32  per core
       L2                                            2x 6   (On-Die, ECC, ASC, Full-Speed)

    Multi CPU:
      ID                                  Formula
      CPU #1                                            Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz, 2833 
      CPU #2                                            Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz, 2833 
      CPU #3                                            Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz, 2833 
      CPU #4                                            Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz, 2833 

       :
                                              775 Contact LGA
                                          3.75 cm x 3.75 cm
                                       820 .
                                  45 nm, CMOS, Cu, High-K Gate
                                         214 mm2
                                   1.150 - 1.250 V
       I/O                                    1.150 - 1.250 V
                                        95 W @ 2.83 GHz

     :
                                                   Intel Corporation
                                     http://ark.intel.com/search.aspx?q=Intel Core 2 Quad Q9550
                                     http://www.aida64.com/driver-updates

     :
       1 /  1                                     0 %
       1 /  2                                     0 %
       1 /  3                                     0 %
       1 /  4                                     0 %


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               GenuineIntel
        CPUID                                      Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
       CPUID                                      00010677h
        IA                            00h  ()
                                  2Ch / MC 10h  (LGA775)
                               705
      HTT / CMP                                         0 / 4
       Tjmax                                 100 C  (212 F)
      CPU Thermal Design Power                          95 W

     :
      64- x86- (AMD64, Intel64)            
      AMD 3DNow!                                         
      AMD 3DNow! Professional                            
      AMD 3DNowPrefetch                                  
      AMD Enhanced 3DNow!                                
      AMD Extended MMX                                   
      AMD FMA4                                           
      AMD MisAligned SSE                                 
      AMD SSE4A                                          
      AMD XOP                                            
      Cyrix Extended MMX                                 
      Enhanced REP MOVSB/STOSB                           
      Float-16 Conversion Instructions                   
      IA-64                                              
      IA BMI1                                            
      IA BMI2                                            
      IA MMX                                            
      IA SSE                                            
      IA SSE2                                           
      IA SSE3                                           
      IA Supplemental SSE3                              
      IA SSE4.1                                         
      IA SSE4.2                                          
      IA AVX                                             
      IA AVX2                                            
      IA FMA                                             
      IA AES Extensions                                  
      VIA Alternate Instruction Set                      
       CLFLUSH                                
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       INVPCID                                 
       LZCNT                                   
       MONITOR / MWAIT                        
       MOVBE                                   
       PCLMULQDQ                               
       POPCNT                                  
       RDFSBASE / RDGSBASE / WRFSBASE / WRGSBASE 
       RDRAND                                  
       RDTSCP                                  
       SKINIT / STGI                           
       SYSCALL / SYSRET                        
       SYSENTER / SYSEXIT                     
      Trailing Bit Manipulation Instructions             
       VIA FEMMS                               

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
         (DEP, NX, EDB)           
          (RNG)         
      PadLock Hash Engine (PHE)                          
      PadLock Montgomery Multiplier (PMM)                
         (PSN)                    

     :
      Automatic Clock Control                           
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                         , 
      Enhanced SpeedStep Technology (EIST, ESS)         , 
      Frequency ID Control                               
      Hardware P-State Control                           
      LongRun                                            
      LongRun Table Interface                            
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                      
      Software Thermal Control                           
                                                
      Thermal Monitor 1                                 
      Thermal Monitor 2                                 
      Thermal Monitoring                                 
      Thermal Trip                                       
      Voltage ID Control                                 

     CPUID:
      1 GB Page Size                                     
      36-bit Page Size Extension                        
      Address Region Registers (ARR)                     
      Core Performance Boost                             
      CPL Qualified Debug Store                         
      Debug Trace Store                                 
      Debugging Extension                               
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Fast Save & Restore                               
      Hyper-Threading Technology (HTT)                   
      Instruction Based Sampling                         
      Invariant Time Stamp Counter                      
      L1 Context ID                                      
      Lightweight Profiling                              
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      Nested Paging                                      
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event                               
      Physical Address Extension (PAE)                  
      Safer Mode Extensions (SMX)                       
      Secure Virtual Machine Extensions (Pacifica)       
      Self-Snoop                                        
      Supervisor Mode Execution Protection (SMEP)        
      Time Stamp Counter (TSC)                          
      Turbo Boost                                        
      Virtual Machine Extensions (Vanderpool)           
      Virtual Mode Extension                            
      Watchdog Timer                                     
      x2APIC                                             
      XGETBV / XSETBV OS Enabled                         
      XSAVE / XRSTOR / XSETBV / XGETBV Extended States   

    CPUID Registers (CPU #1):
      CPUID 00000000                                    0000000A-756E6547-6C65746E-49656E69
      CPUID 00000001                                    00010677-00040800-0008E3FD-BFEBFBFF
      CPUID 00000002                                    05B0B101-005657F0-00000000-2CB4304E
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000004                                    0C000121-01C0003F-0000003F-00000001
      CPUID 00000004                                    0C000122-01C0003F-0000003F-00000001
      CPUID 00000004                                    0C004143-05C0003F-00000FFF-00000001
      CPUID 00000005                                    00000040-00000040-00000003-00000020
      CPUID 00000006                                    00000001-00000002-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000400-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    07280202-00000000-00000000-00000503
      CPUID 80000000                                    80000008-00000000-00000000-00000000
      CPUID 80000001                                    00000000-00000000-00000001-20100000
      CPUID 80000002                                    65746E49-2952286C-726F4320-4D542865
      CPUID 80000003                                    51203229-20646175-55504320-51202020
      CPUID 80000004                                    30353539-20402020-33382E32-007A4847
      CPUID 80000005                                    00000000-00000000-00000000-00000000
      CPUID 80000006                                    00000000-00000000-18008040-00000000
      CPUID 80000007                                    00000000-00000000-00000000-00000000
      CPUID 80000008                                    00003024-00000000-00000000-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    0000000A-756E6547-6C65746E-49656E69
      CPUID 00000001                                    00010677-01040800-0008E3FD-BFEBFBFF
      CPUID 00000002                                    05B0B101-005657F0-00000000-2CB4304E
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000004                                    0C000121-01C0003F-0000003F-00000001
      CPUID 00000004                                    0C000122-01C0003F-0000003F-00000001
      CPUID 00000004                                    0C004143-05C0003F-00000FFF-00000001
      CPUID 00000005                                    00000040-00000040-00000003-00000020
      CPUID 00000006                                    00000001-00000002-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000400-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    07280202-00000000-00000000-00000503
      CPUID 80000000                                    80000008-00000000-00000000-00000000
      CPUID 80000001                                    00000000-00000000-00000001-20100000
      CPUID 80000002                                    65746E49-2952286C-726F4320-4D542865
      CPUID 80000003                                    51203229-20646175-55504320-51202020
      CPUID 80000004                                    30353539-20402020-33382E32-007A4847
      CPUID 80000005                                    00000000-00000000-00000000-00000000
      CPUID 80000006                                    00000000-00000000-18008040-00000000
      CPUID 80000007                                    00000000-00000000-00000000-00000000
      CPUID 80000008                                    00003024-00000000-00000000-00000000

    CPUID Registers (CPU #3):
      CPUID 00000000                                    0000000A-756E6547-6C65746E-49656E69
      CPUID 00000001                                    00010677-02040800-0008E3FD-BFEBFBFF
      CPUID 00000002                                    05B0B101-005657F0-00000000-2CB4304E
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000004                                    0C000121-01C0003F-0000003F-00000001
      CPUID 00000004                                    0C000122-01C0003F-0000003F-00000001
      CPUID 00000004                                    0C004143-05C0003F-00000FFF-00000001
      CPUID 00000005                                    00000040-00000040-00000003-00000020
      CPUID 00000006                                    00000001-00000002-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000400-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    07280202-00000000-00000000-00000503
      CPUID 80000000                                    80000008-00000000-00000000-00000000
      CPUID 80000001                                    00000000-00000000-00000001-20100000
      CPUID 80000002                                    65746E49-2952286C-726F4320-4D542865
      CPUID 80000003                                    51203229-20646175-55504320-51202020
      CPUID 80000004                                    30353539-20402020-33382E32-007A4847
      CPUID 80000005                                    00000000-00000000-00000000-00000000
      CPUID 80000006                                    00000000-00000000-18008040-00000000
      CPUID 80000007                                    00000000-00000000-00000000-00000000
      CPUID 80000008                                    00003024-00000000-00000000-00000000

    CPUID Registers (CPU #4):
      CPUID 00000000                                    0000000A-756E6547-6C65746E-49656E69
      CPUID 00000001                                    00010677-03040800-0008E3FD-BFEBFBFF
      CPUID 00000002                                    05B0B101-005657F0-00000000-2CB4304E
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000004                                    0C000121-01C0003F-0000003F-00000001
      CPUID 00000004                                    0C000122-01C0003F-0000003F-00000001
      CPUID 00000004                                    0C004143-05C0003F-00000FFF-00000001
      CPUID 00000005                                    00000040-00000040-00000003-00000020
      CPUID 00000006                                    00000001-00000002-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000400-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    07280202-00000000-00000000-00000503
      CPUID 80000000                                    80000008-00000000-00000000-00000000
      CPUID 80000001                                    00000000-00000000-00000001-20100000
      CPUID 80000002                                    65746E49-2952286C-726F4320-4D542865
      CPUID 80000003                                    51203229-20646175-55504320-51202020
      CPUID 80000004                                    30353539-20402020-33382E32-007A4847
      CPUID 80000005                                    00000000-00000000-00000000-00000000
      CPUID 80000006                                    00000000-00000000-18008040-00000000
      CPUID 80000007                                    00000000-00000000-00000000-00000000
      CPUID 80000008                                    00003024-00000000-00000000-00000000

    MSR Registers:
      MSR 00000017                                      0810-0000-88C4-C822 [PlatID = 4]
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR 0000002A                                      0000-0000-420C-0000
      MSR 0000008B                                      0000-0705-0000-0000
      MSR 000000CD                                      0000-0000-0000-0804
      MSR 000000CE                                      001A-4822-7F7F-0716
      MSR 000000E7                                      0000-0000-0012-87AA
      MSR 000000E8                                      0000-0000-0012-A28F
      MSR 000000EE                                      0000-0000-877D-5B00
      MSR 0000011E                                      0000-0000-BE70-2111
      MSR 00000198                                      061A-4822-0600-4822
      MSR 00000199                                      0000-0000-0000-4822
      MSR 0000019A                                      0000-0000-0000-0002
      MSR 0000019B                                      0000-0000-0000-0000
      MSR 0000019C                                      0000-0000-8834-0000
      MSR 0000019D                                      0000-0000-0000-061A
      MSR 000001A0                                      0000-0040-6297-2489


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  65-2302-000001-00101111-041510-Eaglelake$A1007001_BIOS DATE: 04/15/10 17:15:35 VER: 08.00.14
                                          Asus Maximus II Formula

      FSB:
                                                 Intel AGTL+
                                              64 
                                         333  (QDR)
                                      1333 
                                   10665 /

      :
                                                 Dual DDR2 SDRAM
                                              128 
       DRAM:FSB                              16:10
                                         533  (DDR)
                                      1067 
                                   17066 /

      :
                                                 Intel Direct Media Interface

        :
                                         1 LGA775
                                       2 PCI, 3 PCI-E x1, 2 PCI-E x16
                                              4 DDR2 DIMM
                                    Audio, Dual Gigabit LAN, IEEE-1394
      -                                       ATX
                                   240 mm x 300 mm
                                    P45
                                   Ultra-ATA/133, SATA-II

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/Motherboards
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates
       BIOS                                   http://www.aida64.com/bios-updates


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   8191 
                                                  1851 
                                                6339 
                                                23 %

       :
                                                   16380 
                                                  1976 
                                                14404 
                                                12 %

     :
                                                   24571 
                                                  3827 
                                                20743 
                                                16 %

     :
                                            C:\pagefile.sys
                                           8191 
      /                           0  / 0 
                                                0 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[ SPD ]---------------------------------------------------------------------------------------------------------

  [ DIMM1: GeIL CL5-5-5DDR21066 5 ]

      :
                                               GeIL CL5-5-5DDR21066 5
                                           00000008h (134217728)
                                              10 / 2008
                                            2  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          5-5-5-15  (CL-RCD-RP-RAS) / 23-51-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 333                                          4-5-5-13  (CL-RCD-RP-RAS) / 20-43-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          3-4-4-10  (CL-RCD-RP-RAS) / 16-34-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   Golden Emperor International Ltd.
                                     http://www.geil.com.tw/products

  [ DIMM2: GeIL CL5-5-5DDR21066 5 ]

      :
                                               GeIL CL5-5-5DDR21066 5
                                           00000008h (134217728)
                                              10 / 2008
                                            2  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          5-5-5-15  (CL-RCD-RP-RAS) / 23-51-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 333                                          4-5-5-13  (CL-RCD-RP-RAS) / 20-43-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          3-4-4-10  (CL-RCD-RP-RAS) / 16-34-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   Golden Emperor International Ltd.
                                     http://www.geil.com.tw/products

  [ DIMM3: GeIL CL5-5-5DDR21066 5 ]

      :
                                               GeIL CL5-5-5DDR21066 5
                                           00000008h (134217728)
                                              10 / 2008
                                            2  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          5-5-5-15  (CL-RCD-RP-RAS) / 23-51-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 333                                          4-5-5-13  (CL-RCD-RP-RAS) / 20-43-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          3-4-4-10  (CL-RCD-RP-RAS) / 16-34-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   Golden Emperor International Ltd.
                                     http://www.geil.com.tw/products

  [ DIMM4: GeIL CL5-5-5DDR21066 5 ]

      :
                                               GeIL CL5-5-5DDR21066 5
                                           00000008h (134217728)
                                              10 / 2008
                                            2  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          5-5-5-15  (CL-RCD-RP-RAS) / 23-51-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 333                                          4-5-5-13  (CL-RCD-RP-RAS) / 20-43-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          3-4-4-10  (CL-RCD-RP-RAS) / 16-34-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   Golden Emperor International Ltd.
                                     http://www.geil.com.tw/products


--------[  ]------------------------------------------------------------------------------------------------------

  [  : Intel Eaglelake P45 ]

      :
                                            Intel Eaglelake P45
       / Stepping                                 02 / A2
                                              1254 Pin FC-BGA
                                          3.4 cm x 3.4 cm
                                  65 nm
                                   1.1 V
      In-Order Queue Depth                              12

     :
                                                     Dual Channel  (128 )
                                           Dual Channel  (128 )

     :
      CAS Latency (CL)                                  5T
      RAS To CAS Delay (tRCD)                           5T
      RAS Precharge (tRP)                               5T
      RAS Active Time (tRAS)                            15T
      Row Refresh Cycle Time (tRFC)                     52T
      Command Rate (CR)                                 2T
      RAS To RAS Delay (tRRD)                           3T
      Write Recovery Time (tWR)                         14T
      Read To Read Delay (tRTR)                         Same Rank: 4T, Different Rank: 5T
      Read To Write Delay (tRTW)                        7T
      Write To Read Delay (tWTR)                        Same Rank: 11T, Different Rank: 5T
      Write To Write Delay (tWTW)                       Same Rank: 4T, Different Rank: 7T
      Read To Precharge Delay (tRTP)                    5T
      Write To Precharge Delay (tWTP)                   14T
      Precharge To Precharge Delay (tPTP)               1T
      Refresh Period (tREF)                             4171T
      DRAM Read ODT                                     3T
      DRAM Write ODT                                    6T
      MCH Read ODT                                      11T
      Performance Level                                 6
      Read Delay Phase Adjust                           Neutral
      DIMM1 Clock Fine Delay                            6T
      DIMM2 Clock Fine Delay                            2T
      DIMM3 Clock Fine Delay                            2T
      DIMM4 Clock Fine Delay                            4T

     :
      ECC                                                
      ChipKill ECC                                       
      RAID                                               
      ECC Scrubbing                                      

     :
       DRAM #1                                    2   (DDR2-800 DDR2 SDRAM)
       DRAM #2                                    2   (DDR2-800 DDR2 SDRAM)
       DRAM #3                                    2   (DDR2-800 DDR2 SDRAM)
       DRAM #4                                    2   (DDR2-800 DDR2 SDRAM)

     PCI Express:
      PCI-E 2.0 x16 port #2                              @ x16  (nVIDIA GF110 - High Definition Audio Controller, Zotac GeForce GTX 580 Video Adapter)

     :
                                                   Intel Corporation
                                     http://www.intel.com/products/chipsets
                                       http://support.intel.com/support/chipsets
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [  : Intel 82801JR ICH10R ]

      :
                                               Intel 82801JR ICH10R
       / Stepping                                 90 / A0
                                              676 Pin mBGA
                                          3.1 cm x 3.1 cm
                                   1.1 V

    High Definition Audio:
                                               Analog Devices AD2000B
      ID                                          11D4989Bh / 10438334h
                                            1003h
                                               Audio

     PCI Express:
      PCI-E 1.0 x1 port #1                              
      PCI-E 1.0 x1 port #3                               @ x1  (Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller)
      PCI-E 1.0 x1 port #4                               @ x1  (Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller)
      PCI-E 1.0 x1 port #5                               @ x1  (Marvell 88SE6121 Serial ATA II Host Controller)

     :
                                                   Intel Corporation
                                     http://www.intel.com/products/chipsets
                                       http://support.intel.com/support/chipsets
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          AMI
       BIOS                                       2302
       BIOS                                  04/15/10
       BIOS                            02/10/11

     BIOS (ATK):
      DRAM Voltage                                      Auto
      CPU Frequency                                     333.00 MHz
      PCIE Frequency                                    100.00 MHz
      DRAM Frequency                                    Auto
      CPU Ratio                                         8.5x

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                   http://www.aida64.com/bios-updates


--------[ ACPI ]--------------------------------------------------------------------------------------------------------

  [ APIC: Multiple APIC Description Table ]

      ACPI:
       ACPI                                      APIC
                                         Multiple APIC Description Table
                                             DFF80390h
                                           108 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMAPIC
      OEM Revision                                      04001015h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      Local APIC Address                                FEE00000h

  [ DSDT: Differentiated System Description Table ]

      ACPI:
       ACPI                                      DSDT
                                         Differentiated System Description Table
                                             DFF80440h
                                           41530 
      OEM ID                                            A1007
      OEM Table ID                                      A1007001
      OEM Revision                                      00000001h
      Creator ID                                        INTL
      Creator Revision                                  20060113h

    nVIDIA SLI:
      SLI Certification                                 
      PCI 0-0-0-0 (Direct I/O)                          8086-2E20  (Intel G43/G45/P43/P45)
      PCI 0-0-0-0 (HAL)                                 8086-2E20  (Intel G43/G45/P43/P45)

  [ FACP: Fixed ACPI Description Table ]

      ACPI:
       ACPI                                      FACP
                                         Fixed ACPI Description Table
                                             DFF80200h
                                           132 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMFACP
      OEM Revision                                      04001015h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      SMI Command Port                                  000000B2h
      PM Timer                                          00000808h

  [ FACS: Firmware ACPI Control Structure ]

      ACPI:
       ACPI                                      FACS
                                         Firmware ACPI Control Structure
                                             DFF8E000h
                                           64 

  [ HPET: IA-PC High Precision Event Timer Table ]

      ACPI:
       ACPI                                      HPET
                                         IA-PC High Precision Event Timer Table
                                             DFF8A680h
                                           56 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMHPET
      OEM Revision                                      04001015h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ MCFG: Memory Mapped Configuration Space Base Address Description Table ]

      ACPI:
       ACPI                                      MCFG
                                         Memory Mapped Configuration Space Base Address Description Table
                                             DFF80400h
                                           60 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMMCFG
      OEM Revision                                      04001015h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ OEMB: OEM Specific Information Table ]

      ACPI:
       ACPI                                      OEMB
                                         OEM Specific Information Table
                                             DFF8E040h
                                           129 
      OEM ID                                            A_M_I_
      OEM Table ID                                      AMI_OEM
      OEM Revision                                      04001015h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ OSFR:  ]

      ACPI:
       ACPI                                      OSFR
                                         
                                             DFF8A6C0h
                                           176 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMOSFR
      OEM Revision                                      04001015h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ RSD PTR: Root System Description Pointer ]

      ACPI:
       ACPI                                      RSD PTR
                                         Root System Description Pointer
                                             000FB2C0h
                                           20 
      OEM ID                                            ACPIAM
      RSDP Revision                                     0
      RSDT Address                                      DFF80000h

  [ RSDT: Root System Description Table ]

      ACPI:
       ACPI                                      RSDT
                                         Root System Description Table
                                             DFF80000h
                                           68 
      OEM ID                                            DELL
      OEM Table ID                                      QA09
      OEM Revision                                      04001015h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      RSDT Entry #0                                     DFF80200h
      RSDT Entry #1                                     DFF80390h
      RSDT Entry #2                                     DFF80400h
      RSDT Entry #3                                     DFF8E040h
      RSDT Entry #4                                     DFF8A680h
      RSDT Entry #5                                     DFF8A6C0h
      RSDT Entry #6                                     DFF8E9D0h
      RSDT Entry #7                                     DFF8A770h

  [ SLIC: Software Licensing Description Table ]

      ACPI:
       ACPI                                      SLIC
                                         Software Licensing Description Table
                                             DFF8A770h
                                           374 
      OEM ID                                            DELL
      OEM Table ID                                      QA09
      OEM Revision                                      42302E31h
      Creator ID                                        NVDA
      Creator Revision                                  0100000Eh
       SLIC                                       2.1

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             DFF8E0D0h
                                           565 
      OEM ID                                            DpgPmm
      OEM Table ID                                      P001Ist
      OEM Revision                                      00000011h
      Creator ID                                        INTL
      Creator Revision                                  20060113h

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             DFF8E310h
                                           565 
      OEM ID                                            DpgPmm
      OEM Table ID                                      P002Ist
      OEM Revision                                      00000012h
      Creator ID                                        INTL
      Creator Revision                                  20060113h

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             DFF8E550h
                                           565 
      OEM ID                                            DpgPmm
      OEM Table ID                                      P003Ist
      OEM Revision                                      00000012h
      Creator ID                                        INTL
      Creator Revision                                  20060113h

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             DFF8E790h
                                           565 
      OEM ID                                            DpgPmm
      OEM Table ID                                      P004Ist
      OEM Revision                                      00000012h
      Creator ID                                        INTL
      Creator Revision                                  20060113h

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             DFF8E9D0h
                                           2684 
      OEM ID                                            DpgPmm
      OEM Table ID                                      CpuPm
      OEM Revision                                      00000012h
      Creator ID                                        INTL
      Creator Revision                                  20060113h


--------[   ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       Vienna
                                                   ()
                                               Multiprocessor Free (64-bit)
                                                6.1.7600 (Win7 RTM)
                                       -
                                         10.07.2010
                                         C:\Windows

     :
                          Aparratus
                           
      ID                                        00426-OEM-8992662-00497
                                            22TKD-F8XX6-YG69F-9M66D-PMJBM
        (WPA)                          

     :
                                           APARRATUS-
                                         Aparratus
                                              Aparratus-
                                             5011  (0 ., 1 , 23 , 31 )

     :
      Common Controls                                   6.16
      Internet Explorer                                 8.0.7600.16385 (IE 8.0 - Windows 7)
      Windows Mail                                      6.1.7600.16385 (win7_rtm.090713-1255)
      Windows Media Player                              12.0.7600.16385 (win7_rtm.090713-1255)
      Windows Messenger                                 -
      MSN Messenger                                     -
      Internet Information Services (IIS)               -
      .NET Framework                                    4.0.30319.1 built by: RTMRel
      Novell Client                                     -
      DirectX                                           DirectX 11.0
      OpenGL                                            6.1.7600.16385 (win7_rtm.090713-1255)
      ASPI                                              -

      :
                                        
       DBCS                                       
                                        
                                     
                                             
                                         
                                         
                                      
                                      


--------[  ]----------------------------------------------------------------------------------------------------

    AEADISRV.EXE             C:\Windows\system32\AEADISRV.EXE                                              64          3576              1 
    aida64.exe               D:\Games\AIDA64 Extreme Edition\aida64.exe                                    32         38648             31 
    armsvc.exe               C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe                  32          4080              1 
    AsSysCtrlService.exe     C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe     32          3408              1 
    audiodg.exe              C:\Windows\system32\AUDIODG.EXE                                               64         22832             21 
    BlueScreenView.exe       C:\Users\Aparratus\Desktop\BlueScreenView.exe                                 32         23304             11 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64          4408              2 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64         15828             16 
    CTAudSvc.exe             C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe                     32          4468              1 
    daemonu.exe              C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe          32          6316              2 
    dwm.exe                  C:\Windows\system32\Dwm.exe                                                   64          6220              1 
    egui.exe                 C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe                           64         13464              5 
    ekrn.exe                 C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe                       32         73740             69 
    explorer.exe             C:\Windows\Explorer.EXE                                                       64         67356             43 
    firefox.exe              D:\Games\FF\firefox.exe                                                       32           271            233 
    icq.exe                  C:\Program Files (x86)\ICQLite\icq.exe                                        32         17248             29 
    jusched.exe              C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe              32          4656              1 
    lsass.exe                C:\Windows\system32\lsass.exe                                                 64         10952              4 
    lsm.exe                  C:\Windows\system32\lsm.exe                                                   64          4388              2 
    mmc.exe                  C:\Windows\system32\mmc.exe                                                   64         13272             52 
    nvSCPAPISvr.exe          C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe           32          5856              2 
    nvtray.exe               C:\Program Files\NVIDIA Corporation\Display\nvtray.exe                        64         13800              7 
    nvvsvc.exe               C:\Windows\system32\nvvsvc.exe                                                64         12780              5 
    nvvsvc.exe               C:\Windows\system32\nvvsvc.exe                                                64          7580              2 
    nvxdsync.exe             C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe                      64         17980              7 
    OctoshapeClient.exe      C:\Users\Aparratus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe  32         10116              6 
    plugin-container.exe     D:\Games\FF\plugin-container.exe                                              32         11204              8 
    plugin-container.exe     D:\Games\FF\plugin-container.exe                                              32           114            150 
    PnkBstrA.exe             C:\Windows\SysWOW64\PnkBstrA.exe                                              32          4336              1 
    razerhid.exe             C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe                          32          7892              2 
    razerofa.exe             C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe                          32          3840              1 
    razertra.exe             C:\Program Files (x86)\Razer\DeathAdder\razertra.exe                          32          6208              3 
    rundll32.exe             C:\Windows\System32\rundll32.exe                                              64          5736              6 
    SeaPort.EXE              C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE                          32          8752              3 
    SearchIndexer.exe        C:\Windows\system32\SearchIndexer.exe                                         64         31020             45 
    services.exe             C:\Windows\system32\services.exe                                              64          9444              5 
    SixEngine.exe            C:\Program Files (x86)\ASUS\EPU-6 Engine\SixEngine.exe                        32          4680             12 
    smax4pnp.exe             C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe                       32          7392              6 
    smss.exe                                                                                               64          1340              0 
    splwow64.exe             C:\Windows\splwow64.exe                                                       64          6300              2 
    spoolsv.exe              C:\Windows\System32\spoolsv.exe                                               64         12324              7 
    sppsvc.exe               C:\Windows\system32\sppsvc.exe                                                64         10852              5 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          5688              2 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         16572             15 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         12820              8 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         30892             66 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          5560              1 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         41824              5 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          9796              4 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          8288              4 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         11520              6 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         39312             40 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         49648             42 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         42744             27 
    System Idle Process                                                                                                     24              0 
    System                                                                                                 64           304              0 
    taskeng.exe              C:\Windows\system32\taskeng.exe                                               64          6272              2 
    taskhost.exe             C:\Windows\system32\taskhost.exe                                              64          9360              8 
    taskhost.exe             C:\Windows\system32\taskhost.exe                                              64         13332              6 
    TnglCtrl.exe             D:\Games\Tunngle\TnglCtrl.exe                                                 32          7920              7 
    VolPanlu.exe             C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe          32         13304             10 
    wininit.exe              C:\Windows\system32\wininit.exe                                               64          4536              1 
    winlogon.exe             C:\Windows\system32\winlogon.exe                                              64          7628              3 
    WLIDSVC.EXE              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE       64         12160              4 
    WLIDSVCM.EXE             C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe      64          3544              1 
    WmiPrvSE.exe             C:\Windows\system32\wbem\wmiprvse.exe                                         32          8812              3 
    WmiPrvSE.exe             C:\Windows\sysWOW64\wbem\wmiprvse.exe                                         64          7580              3 
    wmpnetwk.exe             C:\Program Files\Windows Media Player\wmpnetwk.exe                            64          6664             10 


--------[   ]------------------------------------------------------------------------------------------

    1394ohci         1394 OHCI- -                                   1394ohci.sys          6.1.7600.16385                        
    ACPI              Microsoft ACPI                                                  ACPI.sys              6.1.7600.16385                        
    AcpiPmi          ACPI Power Meter Driver                                                 acpipmi.sys           6.1.7600.16385                        
    ADIHdAudAddService  ADI UAA Function Driver for High Definition Audio Service               ADIHdAud.sys          6.10.2.6600                           
    adp94xx          adp94xx                                                                 adp94xx.sys           1.6.6.4                               
    adpahci          adpahci                                                                 adpahci.sys           1.6.6.1                               
    adpu320          adpu320                                                                 adpu320.sys           7.2.0.0                               
    AFD              Ancillary Function Driver for Winsock                                   afd.sys               6.1.7600.16802                        
    agp440           Intel AGP Bus Filter                                                    agp440.sys            6.1.7600.16385                        
    AIDA64Driver     FinalWire AIDA64 Kernel Driver                                          kerneld.x64                                                 
    aliide           aliide                                                                  aliide.sys            1.2.0.0                               
    amdide           amdide                                                                  amdide.sys            6.1.7600.16385                        
    AmdK8            AMD K8 Processor Driver                                                 amdk8.sys             6.1.7600.16385                        
    AmdPPM           AMD Processor Driver                                                    amdppm.sys            6.1.7600.16385                        
    amdsata          amdsata                                                                 amdsata.sys           1.1.2.4                               
    amdsbs           amdsbs                                                                  amdsbs.sys            3.6.1540.127                          
    amdxata          amdxata                                                                 amdxata.sys           1.1.2.4                               
    AppID             AppID                                                           appid.sys             6.1.7600.16385                        
    arc              arc                                                                     arc.sys               5.2.0.10384                           
    arcsas           arcsas                                                                  arcsas.sys            5.2.0.16119                           
    AsIO             AsIO                                                                    AsIO.sys                                                    
    AsUpIO           AsUpIO                                                                  AsUpIO.sys                                                  
    AsyncMac            RAS                                       asyncmac.sys          6.1.7600.16385                        
    atapi             IDE                                                               atapi.sys             6.1.7600.16385                        
    b06bdrv          Broadcom NetXtreme II VBD                                               bxvbda.sys            4.8.2.0                               
    b57nd60a         Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0                          b57nd60a.sys          10.100.4.0                            
    Beep             Beep                                                                                                                                
    blbdrive         blbdrive                                                                blbdrive.sys          6.1.7600.16385                        
    bowser                                                           bowser.sys            6.1.7600.16765             
    BrFiltLo         Brother USB Mass-Storage Lower Filter Driver                            BrFiltLo.sys          1.10.0.2                              
    BrFiltUp         Brother USB Mass-Storage Upper Filter Driver                            BrFiltUp.sys          1.4.0.1                               
    Brserid          Brother MFC Serial Port Interface Driver (WDM)                          Brserid.sys           1.0.1.6                               
    BrSerWdm         Brother WDM Serial driver                                               BrSerWdm.sys          1.0.0.20                              
    BrUsbMdm         Brother MFC USB Fax Only Modem                                          BrUsbMdm.sys          1.0.0.12                              
    BrUsbSer         Brother MFC USB Serial WDM Driver                                       BrUsbSer.sys          1.0.1.3                               
    BTHMODEM         Bluetooth Serial Communications Driver                                  bthmodem.sys          6.1.7600.16385                        
    cdfs             CD/DVD File System Reader                                               cdfs.sys              6.1.7600.16385             
    cdrom             CD-ROM                                                 cdrom.sys             6.1.7600.16385                        
    circlass         Consumer IR Devices                                                     circlass.sys          6.1.7600.16385                        
    CLFS               (CLFS)                                                     CLFS.sys              6.1.7600.16385                        
    CmBatt           Microsoft ACPI Control Method Battery Driver                            CmBatt.sys            6.1.7600.16385                        
    cmdide           cmdide                                                                  cmdide.sys            2.0.7.0                               
    CNG              CNG                                                                     cng.sys               6.1.7600.16385                        
    Compbatt         Compbatt                                                                compbatt.sys          6.1.7600.16385                        
    CompositeBus                                          CompositeBus.sys      6.1.7600.16385                        
    crcdisk          Crcdisk Filter Driver                                                   crcdisk.sys           6.1.7600.16385                        
    CSC                                                               csc.sys               6.1.7600.16385                        
    danewFltr        NewDeathAdder Mouse                                                     danew.sys             1.0.0.3                               
    DfsC             DFS Namespace Client Driver                                             dfsc.sys              6.1.7600.16804             
    discache         System Attribute Cache                                                  discache.sys          6.1.7600.16385                        
    Disk                                                                         disk.sys              6.1.7600.16385                        
    drmkaud                                                 drmkaud.sys           6.1.7600.16385                        
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           6.1.7600.16432                        
    eamonm           eamonm                                                                  eamonm.sys            4.2.71.0                   
    ebdrv            Broadcom NetXtreme II 10 GigE VBD                                       evbda.sys             4.8.13.0                              
    ehdrv            ehdrv                                                                   ehdrv.sys             4.2.71.0                              
    elxstor          elxstor                                                                 elxstor.sys           7.2.10.211                            
    epfwwfpr         epfwwfpr                                                                epfwwfpr.sys          4.2.71.0                              
    ErrDev           Microsoft Hardware Error Device Driver                                  errdev.sys            6.1.7600.16385                        
    exfat            exFAT File System Driver                                                                                                 
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc                                                        fdc.sys               6.1.7600.16385                        
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          6.1.7600.16385             
    Filetrace        Filetrace                                                               filetrace.sys         6.1.7600.16385             
    flpydisk                                                     flpydisk.sys          6.1.7600.16385                        
    FltMgr                                                                  fltmgr.sys            6.1.7600.16385             
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         6.1.7600.16385             
    fvevol               Bitlocker                              fvevol.sys            6.1.7600.16429                        
    gagp30kx         Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms             gagp30kx.sys          6.1.7600.16385                        
    hcw85cir         Hauppauge Consumer Infrared Receiver                                    hcw85cir.sys          1.31.27127.0                          
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           6.1.7600.16385                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          6.1.7600.16385                        
    HidBatt          HID UPS Battery Driver                                                  HidBatt.sys           6.1.7600.16385                        
    HidBth           Microsoft Bluetooth HID Miniport                                        hidbth.sys            6.1.7600.16385                        
    HidIr            Microsoft Infrared HID Driver                                           hidir.sys             6.1.7600.16385                        
    HidUsb           HID Class Driver                                                        hidusb.sys            6.1.7600.16385                        
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            6.12.4.64                             
    HTTP             HTTP                                                                    HTTP.sys              6.1.7600.16385                        
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          6.1.7600.16385                        
    i8042prt          i8042-     PS/2                          i8042prt.sys          6.1.7600.16385                        
    iaStorV          iaStorV                                                                 iaStorV.sys           8.6.2.1012                            
    iirsp            iirsp                                                                   iirsp.sys             5.4.22.0                              
    intelide         intelide                                                                intelide.sys          6.1.7600.16385                        
    intelppm          Intel                                                 intelppm.sys          6.1.7600.16385                        
    IpFilterDriver     IP-                                              ipfltdrv.sys          6.1.7600.16385                        
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           6.1.7600.16385                        
    IPNAT            IP Network Address Translator                                           ipnat.sys             6.1.7600.16385                        
    IRENUM           IR Bus Enumerator                                                       irenum.sys            6.1.7600.16385                        
    isapnp           isapnp                                                                  isapnp.sys            6.1.7600.16385                        
    iScsiPrt         iScsiPort Driver                                                        msiscsi.sys           6.1.7600.16385                        
    kbdclass                                                          kbdclass.sys          6.1.7600.16385                        
    kbdhid             HID                                                  kbdhid.sys            6.1.7600.16385                        
    KSecDD           KSecDD                                                                  ksecdd.sys            6.1.7600.16385                        
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           6.1.7600.16484                        
    ksthunk          Kernel Streaming Thunks                                                 ksthunk.sys           6.1.7600.16385                        
    lltdio           Link-Layer Topology Discovery Mapper I/O Driver                         lltdio.sys            6.1.7600.16385                        
    LSI_FC           LSI_FC                                                                  lsi_fc.sys            1.28.3.52                             
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.28.3.52                             
    LSI_SAS2         LSI_SAS2                                                                lsi_sas2.sys          2.0.2.71                              
    LSI_SCSI         LSI_SCSI                                                                lsi_scsi.sys          1.28.3.67                             
    luafv                                            luafv.sys             6.1.7600.16385             
    MCfilt           MCfilt                                                                  MCfilt64.sys          6.10.0.8                              
    megasas          megasas                                                                 megasas.sys           4.5.1.64                              
    MegaSR           MegaSR                                                                  MegaSR.sys            13.5.409.2009                         
    Modem            Modem                                                                   modem.sys             6.1.7600.16385                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           6.1.7600.16385                        
    mouclass                                                                mouclass.sys          6.1.7600.16385                        
    mouhid             HID                                                        mouhid.sys            6.1.7600.16385                        
    mountmgr                                                        mountmgr.sys          6.1.7600.16385                        
    mpio             mpio                                                                    mpio.sys              6.1.7600.16385                        
    mpsdrv              Windows                                 mpsdrv.sys            6.1.7600.16385                        
    MRxDAV              WebDav                                 mrxdav.sys            6.1.7600.16385             
    mrxsmb              - SMB                              mrxsmb.sys            6.1.7600.16808             
    mrxsmb10         - SMB 1.x                                            mrxsmb10.sys          6.1.7600.16847             
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          6.1.7600.16808             
    msahci           msahci                                                                  msahci.sys            6.1.7600.16385                        
    msdsm            msdsm                                                                   msdsm.sys             6.1.7600.16385                        
    Msfs             Msfs                                                                                                                     
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         6.1.7600.16385                        
    msisadrv         msisadrv                                                                msisadrv.sys          6.1.7600.16385                        
    MSKSSRV             Microsoft                                   MSKSSRV.sys           6.1.7600.16385                        
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          6.1.7600.16385                        
    MSPQM                Microsoft                     MSPQM.sys             6.1.7600.16385                        
    MsRPC            MsRPC                                                                                                                               
    mssmbios         Microsoft System Management BIOS                                 mssmbios.sys          6.1.7600.16385                        
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             6.1.7600.16385                        
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          6.1.7600.16385                        
    MTsensor         ATK0110 ACPI UTILITY                                                    ASACPI.sys            1043.6.0.0                            
    Mup              Mup                                                                     mup.sys               6.1.7600.16385             
    NativeWifiP      NativeWiFi Filter                                                       nwifi.sys             6.1.7600.16385                        
    NDIS               NDIS                                                  ndis.sys              6.1.7600.16385                        
    NdisCap          NDIS Capture LightWeight Filter                                         ndiscap.sys           6.1.7600.16385                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          6.1.7600.16385                        
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           6.1.7600.16385                        
    NdisWan          NDIS- WAN                                       ndiswan.sys           6.1.7600.16385                        
    NDProxy          NDIS Proxy                                                                                                                          
    NetBIOS          NetBIOS Interface                                                       netbios.sys           6.1.7600.16385             
    NetBT            NetBT                                                                   netbt.sys             6.1.7600.16385                        
    nfrd960          nfrd960                                                                 nfrd960.sys           7.10.0.0                              
    Npfs             Npfs                                                                                                                     
    nsiproxy         NSI proxy service driver.                                               nsiproxy.sys          6.1.7600.16385                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nv_agp           NVIDIA nForce AGP Bus Filter                                            nv_agp.sys            6.1.7600.16385                        
    NVHDA            Service for NVIDIA High Definition Audio Driver                         nvhda64v.sys          1.2.24.0                              
    nvlddmkm         nvlddmkm                                                                nvlddmkm.sys          8.17.12.8562                          
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.16                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.16                             
    ohci1394         1394 OHCI Compliant Host Controller (Legacy)                            ohci1394.sys          6.1.7600.16385                        
    Parport          Parallel port driver                                                    parport.sys           6.1.7600.16385                        
    partmgr                                                                 partmgr.sys           6.1.7600.16385                        
    pci               PCI                                                         pci.sys               6.1.7600.16385                        
    pciide           pciide                                                                  pciide.sys            6.1.7600.16385                        
    pcmcia           pcmcia                                                                  pcmcia.sys            6.1.7600.16385                        
    pcw              Performance Counters for Windows Driver                                 pcw.sys               6.1.7600.16385                        
    PEAUTH           PEAUTH                                                                  peauth.sys            6.1.7600.16385                        
    PptpMiniport     - WAN (PPTP)                                                    raspptp.sys           6.1.7600.16385                        
    Processor        Processor Driver                                                        processr.sys          6.1.7600.16385                        
    Psched             QoS                                                 pacer.sys             6.1.7600.16385                        
    ql2300           ql2300                                                                  ql2300.sys            9.1.8.6                               
    ql40xx           ql40xx                                                                  ql40xx.sys            2.1.3.20                              
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          6.1.7600.16385                        
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            6.1.7600.16385                        
    RasAgileVpn      WAN Miniport (IKEv2)                                                    AgileVpn.sys          6.1.7600.16385                        
    Rasl2tp          - WAN (L2TP)                                                    rasl2tp.sys           6.1.7600.16385                        
    RasPppoe          PPPOE                                          raspppoe.sys          6.1.7600.16385                        
    RasSstp          - WAN (SSTP)                                                    rassstp.sys           6.1.7600.16385                        
    rdbss                                               rdbss.sys             6.1.7600.16385             
    rdpbus           Remote Desktop Device Redirector Bus Driver                             rdpbus.sys            6.1.7600.16385                        
    RDPCDD           RDPCDD                                                                  RDPCDD.sys            6.1.7600.16385                        
    RDPDR            Terminal Server Device Redirector Driver                                rdpdr.sys             6.1.7600.16385                        
    RDPENCDD         RDP Encoder Mirror Driver                                               rdpencdd.sys          6.1.7600.16385                        
    RDPREFMP         Reflector Display Driver used to gain access to graphics data           rdprefmp.sys          6.1.7600.16385                        
    RDPWD            RDP Winstation Driver                                                                                                               
    rdyboost         ReadyBoost                                                              rdyboost.sys          6.1.7600.16385                        
    rspndr           Link-Layer Topology Discovery Responder                                 rspndr.sys            6.1.7600.16385                        
    RTL8023x64        Realtek 10/100 NIC Family NDIS x64                              Rtnic64.sys           6.109.530.2008                        
    s3cap            s3cap                                                                   vms3cap.sys           6.1.7600.16385                        
    sbp2port         sbp2port                                                                sbp2port.sys          6.1.7600.16385                        
    scfilter           -  PnP                                  scfilter.sys          6.1.7600.16385                        
    secdrv           Security Driver                                                                                                                     
    Serenum          Serenum Filter Driver                                                   serenum.sys           6.1.7600.16385                        
    Serial           Serial                                                                  serial.sys            6.1.7600.16385                        
    sermouse         Serial Mouse Driver                                                     sermouse.sys          6.1.7600.16385                        
    sffdisk          SFF Storage Class Driver                                                sffdisk.sys           6.1.7600.16385                        
    sffp_mmc         SFF Storage Protocol Driver for MMC                                     sffp_mmc.sys          6.1.7600.16385                        
    sffp_sd          SFF Storage Protocol Driver for SDBus                                   sffp_sd.sys           6.1.7600.16385                        
    sfloppy          High-Capacity Floppy Disk Drive                                         sfloppy.sys           6.1.7600.16385                        
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    Smb                TCP/IP  TCP/IPv6 ( SMB)                        smb.sys               6.1.7600.16385                        
    spldr            Security Processor Loader Driver                                                                                                    
    sptd             sptd                                                                    sptd.sys                                                    
    srv                Server SMB 1.xxx                                        srv.sys               6.1.7600.16806             
    srv2               Server SMB 2.xxx                                        srv2.sys              6.1.7600.16806             
    srvnet           srvnet                                                                  srvnet.sys            6.1.7600.16806             
    StarOpen         StarOpen                                                                                                                 
    stexstor         stexstor                                                                stexstor.sys          5.0.1.1                               
    storflt                                   vmstorfl.sys          6.1.7600.16385                        
    storvsc          storvsc                                                                 storvsc.sys           6.1.7600.16385                        
    swenum                                                             swenum.sys            6.1.7600.16385                        
    tap0901t         TAP-Win32 Adapter V9 (Tunngle)                                          tap0901t.sys          9.0.0.6                               
    Tcpip              TCP/IP                                                tcpip.sys             6.1.7600.16839                        
    TCPIP6           Microsoft IPv6 Protocol Driver                                          tcpip.sys             6.1.7600.16839                        
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          6.1.7600.16385                        
    TDPIPE           TDPIPE                                                                  tdpipe.sys            6.1.7600.16385                        
    TDTCP            TDTCP                                                                   tdtcp.sys             6.1.7600.16385                        
    tdx                NetIO Legacy TDI                                      tdx.sys               6.1.7600.16385                        
    TermDD                                                         termdd.sys            6.1.7600.16385                        
    tssecsrv         Remote Desktop Services Security Filter Driver                          tssecsrv.sys          6.1.7600.16385                        
    tunnel                Microsoft                        tunnel.sys            6.1.7600.16385                        
    uagp35           Microsoft AGPv3.5 Filter                                                uagp35.sys            6.1.7600.16385                        
    udfs             udfs                                                                    udfs.sys              6.1.7600.16385             
    uliagpkx         Uli AGP Bus Filter                                                      uliagpkx.sys          6.1.7600.16385                        
    umbus            UMBus                                               umbus.sys             6.1.7600.16385                        
    UmPass           Microsoft UMPass Driver                                                 umpass.sys            6.1.7600.16385                        
    usbccgp              USB (Microsoft)         usbccgp.sys           6.1.7600.16385                        
    usbcir           eHome Infrared Receiver (USBCIR)                                        usbcir.sys            6.1.7600.16385                        
    usbehci            Microsoft USB 2.0  -       usbehci.sys           6.1.7600.16385                        
    usbhub             USB- ()                      usbhub.sys            6.1.7600.16385                        
    usbohci          Microsoft USB Open Host Controller Miniport Driver                      usbohci.sys           6.1.7600.16385                        
    usbprint           Microsoft USB                                           usbprint.sys          6.1.7600.16385                        
    usbscan           USB-                                                     usbscan.sys           6.1.7600.16385                        
    USBSTOR              USB                                  USBSTOR.SYS           6.1.7600.16385                        
    usbuhci            Microsoft USB  -         usbuhci.sys           6.1.7600.16385                        
    VCSVADHWSer      Avnex Virtual Audio Device (WDM)                                        vcsvad.sys            1.0.0.1                               
    vdrvroot             ()                   vdrvroot.sys          6.1.7600.16385                        
    vga              vga                                                                     vgapnp.sys            6.1.7600.16385                        
    VgaSave          VgaSave                                                                 vga.sys               6.1.7600.16385                        
    vhdmp            vhdmp                                                                   vhdmp.sys             6.1.7600.16385                        
    vhidmini         Razer Gaming Device                                                     vHidDev.sys           6.1.7600.16385                        
    viaide           viaide                                                                  viaide.sys            6.0.6000.170                          
    vmbus             VMBus                                                              vmbus.sys             6.1.7600.16385                        
    VMBusHID         VMBusHID                                                                VMBusHID.sys          6.1.7600.16385                        
    volmgr                                                             volmgr.sys            6.1.7600.16385                        
    volmgrx                                                        volmgrx.sys           6.1.7600.16385                        
    volsnap                                                         volsnap.sys           6.1.7600.16385                        
    vsmraid          vsmraid                                                                 vsmraid.sys           6.0.6000.6210                         
    vwifibus           Virtual WiFi                                               vwifibus.sys          6.1.7600.16385                        
    WacomPen         Wacom Serial Pen HID Driver                                             wacompen.sys          6.1.7600.16385                        
    WANARP              IP ARP                                       wanarp.sys            6.1.7600.16385                        
    Wanarpv6            IPv6 ARP                                     wanarp.sys            6.1.7600.16385                        
    Wd               Wd                                                                      wd.sys                6.1.7600.16385                        
    Wdf01000         Kernel Mode Driver Frameworks service                                   Wdf01000.sys          1.9.7600.16385                        
    WfpLwf           WFP Lightweight Filter                                                  wfplwf.sys            6.1.7600.16385                        
    WIMMount         WIMMount                                                                wimmount.sys          6.1.7600.16385             
    WinUsb           WinUsb                                                                  WinUsb.sys            6.1.7600.16385                        
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           6.1.7600.16385                        
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           6.1.7600.16385                        
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            6.1.7600.16385                        
    WUDFRd           WUDFRd                                                                  WUDFRd.sys            6.1.7600.16385                        
    yukonw7          NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller           yk62x64.sys           11.10.5.3                             


--------[  ]------------------------------------------------------------------------------------------------------

    AdobeARMservice                    Adobe Acrobat Update Service                                            armsvc.exe            1.5.5.0                        LocalSystem
    AEADIFilters                       Andrea ADI Filters Service                                              AEADISRV.EXE          1.0.64.12                      LocalSystem
    AeLookupSvc                                                              svchost.exe           6.1.7600.16385                       localSystem
    ALG                                                                             alg.exe               6.1.7600.16385                 NT AUTHORITY\LocalService
    AppIDSvc                                                                            svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    AppMgmt                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    aspnet_state                       ASP.NET State Service                                                   aspnet_state.exe      4.0.30319.1                    NT AUTHORITY\NetworkService
    AsSysCtrlService                   ASUS System Control Service                                             AsSysCtrlService.exe                                 LocalSystem
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           6.1.7600.16385                       LocalSystem
    AudioSrv                           Windows Audio                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           6.1.7600.16385                       LocalSystem
    BBSvc                              Bing Bar Update Service                                                 BBSvc.EXE             7.0.822.0                      LocalSystem
    BBUpdate                           BBUpdate                                                                SeaPort.EXE           3.1.163.0                      LocalSystem
    BDESVC                                BitLocker                                      svchost.exe           6.1.7600.16385                       localSystem
    BFE                                                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           6.1.7600.16385                       LocalSystem
    Browser                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    bthserv                              Bluetooth                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    CertPropSvc                                                                      svchost.exe           6.1.7600.16385                       LocalSystem
    clr_optimization_v2.0.50727_32     Microsoft .NET Framework NGEN v2.0.50727_X86                            mscorsvw.exe          2.0.50727.4927                 LocalSystem
    clr_optimization_v2.0.50727_64     Microsoft .NET Framework NGEN v2.0.50727_X64                            mscorsvw.exe          2.0.50727.4927                 LocalSystem
    clr_optimization_v4.0.30319_32     Microsoft .NET Framework NGEN v4.0.30319_X86                            mscorsvw.exe          4.0.30319.1                    LocalSystem
    clr_optimization_v4.0.30319_64     Microsoft .NET Framework NGEN v4.0.30319_X64                            mscorsvw.exe          4.0.30319.1                    LocalSystem
    COMSysApp                            COM+                                               dllhost.exe           6.1.7600.16385                 LocalSystem
    Creative ALchemy AL6 Licensing Service  Creative ALchemy AL6 Licensing Service                                  AL6Licensing.exe      2.80.12.6                      LocalSystem
    Creative Audio Engine Licensing Service  Creative Audio Engine Licensing Service                                 CTAELicensing.exe     2.80.12.6                      LocalSystem
    CryptSvc                                                                                 svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    CscService                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    CTAudSvcService                    Creative Audio Service                                                  CTAudSvc.exe          3.11.0.0                       LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           6.1.7600.16385                       LocalSystem
    defragsvc                                                                               svchost.exe           6.1.7600.16385                 localSystem
    Dhcp                               DHCP-                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Dnscache                           DNS-                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    dot3svc                                                                              svchost.exe           6.1.7600.16385                       localSystem
    DPS                                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EapHost                                (EAP)                         svchost.exe           6.1.7600.16385                       localSystem
    EFS                                   (EFS)                                      lsass.exe             6.1.7600.16385                       LocalSystem
    ehRecvr                              Windows Media Center                                    ehRecvr.exe           6.1.7600.16590                 NT AUTHORITY\networkService
    ehSched                              Windows Media Center                                ehsched.exe           6.1.7600.16385                 NT AUTHORITY\networkService
    EhttpSrv                           ESET HTTP Server                                                        EHttpSrv.exe          4.2.71.3                       NT AUTHORITY\NetworkService
    ekrn                               ESET Service                                                            ekrn.exe              4.2.71.3                       LocalSystem
    eventlog                             Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Fax                                                                                                    fxssvc.exe            6.1.7600.16385                 NT AUTHORITY\NetworkService
    fdPHost                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache                             Windows                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.4902                  NT Authority\LocalService
    gpsvc                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    hidserv                              HID-                                                svchost.exe           6.1.7600.16385                       LocalSystem
    hkmsvc                                                      svchost.exe           6.1.7600.16385                       localSystem
    HomeGroupListener                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    HomeGroupProvider                                                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    idsvc                              Windows CardSpace                                                       infocard.exe          3.0.4506.4926                        LocalSystem
    IKEEXT                               IPsec        IP     svchost.exe           6.1.7600.16385                       LocalSystem
    IPBusEnum                           IP- PnP-X                                              svchost.exe           6.1.7600.16385                       LocalSystem
    iphlpsvc                             IP                                               svchost.exe           6.1.7600.16385                       LocalSystem
    KeyIso                               CNG                                                     lsass.exe             6.1.7600.16385                       LocalSystem
    KtmRm                              KtmRm                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    LanmanWorkstation                                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    lltdsvc                                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Mcx2Svc                              Media Center                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MMCSS                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    MpsSvc                              Windows                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MSDTC                                                                   msdtc.exe             2001.12.8530.16385                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           6.1.7600.16385                       LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.7600.16385                 LocalSystem
    napagent                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Netlogon                                                                                lsass.exe             6.1.7600.16385                       LocalSystem
    Netman                                                                                   svchost.exe           6.1.7600.16385                       LocalSystem
    NetMsmqActivator                     Net.Msmq                                         SMSvcHost.exe         4.0.30319.1                          NT AUTHORITY\NetworkService
    NetPipeActivator                     Net.Pipe                                         SMSvcHost.exe         4.0.30319.1                          NT AUTHORITY\LocalService
    netprofm                                                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    NetTcpActivator                      Net.Tcp                                          SMSvcHost.exe         4.0.30319.1                          NT AUTHORITY\LocalService
    NetTcpPortSharing                       Net.Tcp                                  SMSvcHost.exe         4.0.30319.1                          NT AUTHORITY\LocalService
    NlaSvc                                                                     svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    nvsvc                              NVIDIA Display Driver Service                                           nvvsvc.exe            8.17.12.8562                   LocalSystem
    nvUpdatusService                   NVIDIA Update Service Daemon                                            daemonu.exe           1.5.20.0                       .\UpdatusUser
    p2pimsvc                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    PerfHost                                                           perfhost.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    pla                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PlugPlay                           Plug-and-Play                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    PnkBstrA                           PnkBstrA                                                                PnkBstrA.exe                                         LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Power                                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    ProfSvc                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    ProtectedStorage                                                                        lsass.exe             6.1.7600.16385                       LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           6.1.7600.16385                       localSystem
    RasMan                                                                svchost.exe           6.1.7600.16385                       localSystem
    RemoteAccess                                                                  svchost.exe           6.1.7600.16385                       localSystem
    RemoteRegistry                                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RpcEptMapper                          RPC                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           6.1.7600.16385                 NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    SamSs                                                                   lsass.exe             6.1.7600.16385                       LocalSystem
    SCardSvr                           -                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Schedule                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    SCPolicySvc                          -                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SDRSVC                              Windows                                                       svchost.exe           6.1.7600.16385                 localSystem
    seclogon                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    SENS                                                                    svchost.exe           6.1.7600.16385                       LocalSystem
    SensrSvc                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           6.1.7600.16385                       localSystem
    SharedAccess                             (ICS)                            svchost.exe           6.1.7600.16385                       LocalSystem
    ShellHWDetection                                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SNMPTRAP                            SNMP                                                            snmptrap.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           6.1.7600.16661                 LocalSystem
    sppsvc                                                                        sppsvc.exe            6.1.7600.16385                 NT AUTHORITY\NetworkService
    sppuinotify                          SPP                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SSDPSRV                             SSDP                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SstpSvc                             SSTP                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Steam Client Service               Steam Client Service                                                    Program                                              LocalSystem
    Stereo Service                     NVIDIA Stereoscopic 3D Driver Service                                   nvSCPAPISvr.exe       7.17.12.8562                   LocalSystem
    stisvc                                Windows (WIA)                               svchost.exe           6.1.7600.16385                 NT Authority\LocalService
    swprv                                  (Microsoft)                  svchost.exe           6.1.7600.16385                 LocalSystem
    SysMain                            Superfetch                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    TabletInputService                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TapiSrv                                                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    TBS                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TermService                                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    THREADORDER                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TrkWks                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  6.1.7600.16385                 localSystem
    TunngleService                     TunngleService                                                          TnglCtrl.exe          4.3.2.0                        LocalSystem
    UI0Detect                                                                     UI0Detect.exe         6.1.7600.16385                 LocalSystem
    UmRdpService                                svchost.exe           6.1.7600.16385                       localSystem
    upnphost                             PNP-                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    UxSms                                                           svchost.exe           6.1.7600.16385                       localSystem
    VaultSvc                                                                             lsass.exe             6.1.7600.16385                       LocalSystem
    vds                                                                                         vds.exe               6.1.7600.16385                 LocalSystem
    VSS                                                                                  vssvc.exe             6.1.7600.16385                 LocalSystem
    W32Time                              Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WatAdminSvc                           Windows                                     WatAdminSvc.exe       7.1.7600.16395                 LocalSystem
    wbengine                                                                wbengine.exe          6.1.7600.16385                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wcncsvc                              Windows -                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WcsPlugInService                     Windows (WCS)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WebClient                          -                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    wercplsupport                          "     "  svchost.exe           6.1.7600.16385                       localSystem
    WerSvc                                Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinDefend                           Windows                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Wlansvc                              WLAN                                               svchost.exe           6.1.7600.16385                       LocalSystem
    wlidsvc                            Windows Live ID Sign-in Assistant                                       WLIDSVC.EXE           6.500.3165.0                   LocalSystem
    wmiApSrv                           WMI Performance Adapter                                                 WmiApSrv.exe          6.1.7600.16385                 localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe                                         NT AUTHORITY\NetworkService
    WPCSvc                             Parental Controls                                                       svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    WPDBusEnum                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wscsvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.7600.16385                 LocalSystem
    wuauserv                             Windows                                                svchost.exe           6.1.7600.16385                       LocalSystem
    wudfsvc                            Windows Driver Foundation - User-mode Driver Framework                  svchost.exe           6.1.7600.16385                       LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService


--------[  AX ]----------------------------------------------------------------------------------------------------

    bdaplgin.ax                6.1.7600.16385              Microsoft BDA Device Control Plug-in for MPEG2 based networks.
    g711codc.ax                6.1.7600.16385              Intel G711 CODEC
    iac25_32.ax                2.0.5.53                      Indeo audio
    ir41_32.ax                 4.51.16.3                   Intel Indeo Video 4.5
    ivfsrc.ax                  5.10.2.51                    Intel Indeo video IVF  5.10
    ksproxy.ax                 6.1.7600.16385              WDM Streaming ActiveMovie Proxy
    kstvtune.ax                6.1.7600.16385               - WDM
    kswdmcap.ax                6.1.7600.16385                WDM
    ksxbar.ax                  6.1.7600.16385              WDM Streaming Crossbar
    mpeg2data.ax               6.6.7600.16385              Microsoft MPEG-2 Section and Table Acquisition Module
    mpg2splt.ax                6.6.7600.16724              DirectShow MPEG-2 Splitter.
    msdvbnp.ax                 6.6.7600.16385              Microsoft Network Provider for MPEG2 based networks.
    msnp.ax                    6.6.7600.16590              Microsoft Network Provider for MPEG2 based networks.
    psisrndr.ax                6.6.7600.16385              Microsoft Transport Information Filter for MPEG2 based networks.
    vbicodec.ax                6.6.7600.16385              Microsoft VBI Codec
    vbisurf.ax                 6.1.7600.16385              VBI Surface Allocator Filter
    vidcap.ax                  6.1.7600.16385              Video Capture Interface Server
    wstpager.ax                6.6.7600.16385              Microsoft Teletext Server


--------[  DLL ]---------------------------------------------------------------------------------------------------

    aaclient.dll               6.1.7600.16385                  
    accessibilitycpl.dll       6.1.7600.16385                 
    acctres.dll                6.1.7600.16385                     (Microsoft)
    acledit.dll                6.1.7600.16385                 ACL
    aclui.dll                  6.1.7600.16385                
    acppage.dll                6.1.7600.16385                  ""
    actioncenter.dll           6.1.7600.16385               
    actioncentercpl.dll        6.1.7600.16385                 
    activeds.dll               6.1.7600.16385               DLL   AD
    actxprxy.dll               6.1.7600.16385              ActiveX Interface Marshaling Library
    admparse.dll               8.0.7600.16385              IEAK Global Policy Template Parser
    admtmpl.dll                6.1.7600.16385               " "
    adprovider.dll             6.1.7600.16385               DLL adprovider
    adsldp.dll                 6.1.7600.16385              ADs LDAP Provider DLL
    adsldpc.dll                6.1.7600.16385               DLL  LDAP AD
    adsmsext.dll               6.1.7600.16385              ADs LDAP Provider DLL
    adsnt.dll                  6.1.7600.16385               DLL    Windows NT
    adtschema.dll              6.1.7600.16385                 
    advapi32.dll               6.1.7600.16385                API Windows 32
    advpack.dll                8.0.7600.16385              ADVPACK
    aecache.dll                6.1.7600.16385              AECache Sysprep Plugin
    aeevts.dll                 6.1.7600.16385                  
    alttab.dll                 6.1.7600.16385              Windows Shell Alt Tab
    amstream.dll               6.6.7600.16385              DirectShow Runtime.
    amxread.dll                6.1.7600.16385              API Tracing Manifest Read Library
    apds.dll                   6.1.7600.16385                  Microsoft
    apilogen.dll               6.1.7600.16385                 API
    api-ms-win-core-console-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-file-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-handle-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-heap-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-localization-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-localregistry-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-misc-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-profile-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-string-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-synch-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-util-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-security-base-l1-1-0.dll  6.1.7600.16850              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-sddl-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l2-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    apircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    apisetschema.dll           6.1.7600.16385              ApiSet Schema DLL
    apomngr.dll                1.0.249.0                   
    apphelp.dll                6.1.7600.16385                 
    apphlpdm.dll               6.1.7600.16385                 
    appidapi.dll               6.1.7600.16385               API-  
    appidpolicyengineapi.dll   6.1.7600.16385              AppId Policy Engine API Module
    appmgmts.dll               6.1.7600.16385                
    appmgr.dll                 6.1.7600.16385                 
    apss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    asferror.dll               12.0.7600.16385               ASF
    asio.dll                   1.0.0.1                     AsIO DLL
    aspnet_counters.dll        4.0.30319.1                 Microsoft ASP.NET Performance Counter Shim DLL
    asycfilt.dll               6.1.7600.16544              
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atl100.dll                 10.0.30319.415              ATL Module for Windows
    atmfd.dll                  5.1.2.234                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.234                   Windows NT OpenType/Type 1 API Library.
    audiodev.dll               6.1.7600.16385                   
    audioeng.dll               6.1.7600.16385              Audio Engine
    audiokse.dll               6.1.7600.16385              Audio Ks Endpoint
    audioses.dll               6.1.7600.16385                
    auditnativesnapin.dll      6.1.7600.16385                    
    auditpolicygpinterop.dll   6.1.7600.16385                 
    auditpolmsg.dll            6.1.7600.16385                MMC  
    authfwcfg.dll              6.1.7600.16385               Windows      
    authfwgp.dll               6.1.7600.16385               Windows c      
    authfwsnapin.dll           6.1.7600.16385              Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           6.1.7600.16385              Wizard Framework
    authui.dll                 6.1.7600.16385                
    authz.dll                  6.1.7600.16385              Authorization Framework
    autoplay.dll               6.1.7600.16385               ( )
    auxiliarydisplayapi.dll    6.1.7600.16385              Microsoft Windows SideShow API
    auxiliarydisplaycpl.dll    6.1.7600.16385                Microsoft Windows SideShow
    avicap32.dll               6.1.7600.16385                 AVI
    avifil32.dll               6.1.7600.16490                 AVI
    avrt.dll                   6.1.7600.16385              Multimedia Realtime Runtime
    azroles.dll                6.1.7600.16385              azroles Module
    azroleui.dll               6.1.7600.16385               
    azsqlext.dll               6.1.7600.16385              AzMan Sql Audit Extended Stored Procedures Dll
    basecsp.dll                6.1.7600.16385                 - (Microsoft)
    batmeter.dll               6.1.7600.16385              Battery Meter Helper DLL
    bcrypt.dll                 6.1.7600.16385              Windows Cryptographic Primitives Library (Wow64)
    bcryptprimitives.dll       6.1.7600.16385              Windows Cryptographic Primitives Library
    bidispl.dll                6.1.7600.16385              Bidispl DLL
    biocredprov.dll            6.1.7600.16385                 WinBio
    bitsperf.dll               7.5.7600.16385              Perfmon Counter Access
    bitsprx2.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    bitsprx3.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.0 Proxy
    bitsprx4.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.5 Proxy
    bitsprx5.dll               7.5.7600.16385              Background Intelligent Transfer Service 3.0 Proxy
    bitsprx6.dll               7.5.7600.16385              Background Intelligent Transfer Service 4.0 Proxy
    blackbox.dll               11.0.7600.16385             BlackBox DLL
    bootvid.dll                6.1.7600.16385              VGA Boot Driver
    browcli.dll                6.1.7600.16385              Browser Service Client DLL
    browseui.dll               6.1.7600.16385              Shell Browser UI Library
    btpanui.dll                6.1.7600.16385                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    bwunpairelevated.dll       6.1.7600.16385              BWUnpairElevated Proxy Dll
    c_g18030.dll               6.1.7600.16385              GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               6.1.7600.16385              ISO-2022 Code Page Translation DLL
    c_iscii.dll                6.1.7600.16385              ISCII Code Page Translation DLL
    cabinet.dll                6.1.7600.16385              Microsoft Cabinet File API
    cabview.dll                6.1.7600.16500                 CAB-
    capiprovider.dll           6.1.7600.16385               DLL capiprovider
    capisp.dll                 6.1.7600.16385              Sysprep cleanup dll for CAPI
    catsrv.dll                 2001.12.8530.16385          COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Utilities
    cca.dll                    6.6.7600.16385              CCA DirectShow Filter.
    cdosys.dll                 6.6.7600.16385              Microsoft CDO for Windows Library
    certcli.dll                6.1.7600.16385                 Microsoft Active Directory
    certcredprovider.dll       6.1.7600.16385                 
    certenc.dll                6.1.7600.16385              Active Directory Certificate Services Encoding
    certenroll.dll             6.1.7600.16418                  Active Directory Microsoft
    certenrollui.dll           6.1.7600.16385                  X509
    certmgr.dll                6.1.7600.16385                
    certpoleng.dll             6.1.7600.16385                
    cewmdm.dll                 12.0.7600.16385               Windows CE WMDM
    cfgbkend.dll               6.1.7600.16385              Configuration Backend Interface
    cfgmgr32.dll               6.1.7600.16820              Configuration Manager DLL
    chsbrkr.dll                6.1.7600.16385              Simplified Chinese Word Breaker
    chtbrkr.dll                6.1.7600.16385              Chinese Traditional Word Breaker
    chxreadingstringime.dll    6.1.7600.16385              CHxReadingStringIME
    cic.dll                    6.1.7600.16385                CIC - MMC   
    clb.dll                    6.1.7600.16385                
    clbcatq.dll                2001.12.8530.16385          COM+ Configuration Catalog
    clfsw32.dll                6.1.7600.16385              Common Log Marshalling Win32 DLL
    cliconfg.dll               6.1.7600.16385              SQL Client Configuration Utility DLL
    clusapi.dll                6.1.7600.16385               API 
    cmcfg32.dll                7.2.7600.16385                  Microsoft
    cmdial32.dll               7.2.7600.16385               
    cmdrtr.dll                 1.0.60.0                    
    cmicryptinstall.dll        6.1.7600.16385              Installers for cryptographic elements of CMI objects
    cmifw.dll                  6.1.7600.16385              Windows Firewall rule configuration plug-in
    cmipnpinstall.dll          6.1.7600.16385              PNP plugin installer for CMI
    cmlua.dll                  7.2.7600.16385                API   
    cmpbk32.dll                7.2.7600.16385              Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.7600.16385                API      
    cmutil.dll                 7.2.7600.16385                  (Microsoft)
    cngaudit.dll               6.1.7600.16385              Windows Cryptographic Next Generation audit library
    cngprovider.dll            6.1.7600.16385               DLL cngprovider
    cnvfat.dll                 6.1.7600.16385              FAT File System Conversion Utility DLL
    colbact.dll                2001.12.8530.16385          COM+
    colorcnv.dll               6.1.7600.16385              Windows Media Color Conversion
    colorui.dll                6.1.7600.16385                 
    comcat.dll                 6.1.7600.16385              Microsoft Component Category Manager Library
    comctl32.dll               5.82.7600.16661                  
    comdlg32.dll               6.1.7600.16385                 
    compobj.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    compstui.dll               6.1.7600.16385                   
    comrepl.dll                2001.12.8530.16385          COM+
    comres.dll                 2001.12.8530.16385           COM+
    comsnap.dll                2001.12.8530.16385          COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.8530.16385          COM+ Services
    comuid.dll                 2001.12.8530.16385          COM+ Explorer UI
    connect.dll                6.1.7600.16385               
    console.dll                6.1.7600.16385                 
    corpol.dll                 8.0.7600.16385              Microsoft COM Runtime Execution Engine
    cpfilters.dll              6.6.7600.16724               PTFilter & Encypter/Decrypter Tagger Filters.
    credssp.dll                6.1.7600.16385              Credential Delegation Security Package
    credui.dll                 6.1.7600.16385                 
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                6.1.7600.16385              API32 
    cryptbase.dll              6.1.7600.16385              Base cryptographic API DLL
    cryptdlg.dll               6.1.7600.16385                
    cryptdll.dll               6.1.7600.16385              Cryptography Manager
    cryptext.dll               6.1.7600.16385                
    cryptnet.dll               6.1.7600.16385              Crypto Network Related API
    cryptsp.dll                6.1.7600.16385              Cryptographic Service Provider API
    cryptsvc.dll               6.1.7600.16385               
    cryptui.dll                6.1.7600.16385                
    cryptxml.dll               6.1.7600.16385              API- XML DigSig
    cscapi.dll                 6.1.7600.16385              Offline Files Win32 API
    cscdll.dll                 6.1.7600.16385              Offline Files Temporary Shim
    cscobj.dll                 6.1.7600.16385               COM-   CSC API
    csver.dll                  9.1.1.1019                  CSVer
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    cttele32.dll               1.0.18.0                    Creative Common PS Module
    d2d1.dll                   6.1.7600.16385              Microsoft D2D Library
    d3d10.dll                  6.1.7600.16385              Direct3D 10 Runtime
    d3d10_1.dll                6.1.7600.16385              Direct3D 10.1 Runtime
    d3d10_1core.dll            6.1.7600.16385              Direct3D 10.1 Runtime
    d3d10core.dll              6.1.7600.16385              Direct3D 10 Runtime
    d3d10level9.dll            6.1.7600.16385              Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              6.1.7600.16385              Direct3D 10 Rasterizer
    d3d11.dll                  6.1.7600.16385              Direct3D 11 Runtime
    d3d8.dll                   6.1.7600.16385              Microsoft Direct3D
    d3d8thk.dll                6.1.7600.16385              Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   6.1.7600.16385              Direct3D 9 Runtime
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  6.1.7600.16385              Microsoft Direct3D
    d3dim700.dll               6.1.7600.16385              Microsoft Direct3D
    d3dramp.dll                6.1.7600.16385              Microsoft Direct3D
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 6.1.7600.16385              DirectX Files DLL
    dataclen.dll               6.1.7600.16385                 Windows
    davclnt.dll                6.1.7600.16385              Web DAV Client DLL
    davhlpr.dll                6.1.7600.16385              DAV Helper DLL
    dbgeng.dll                 6.1.7600.16385              Windows Symbolic Debugger Engine
    dbghelp.dll                6.1.7600.16385              Windows Image Helper
    dbnetlib.dll               6.1.7600.16385              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               6.1.7600.16385              Named Pipes Net DLL for SQL Clients
    dciman32.dll               6.1.7600.16385              DCI Manager
    ddaclsys.dll               6.1.7600.16385              SysPrep module for Reseting Data Drive ACL 
    ddoiproxy.dll              6.1.7600.16385              DDOI Interface Proxy
    ddores.dll                 6.1.7600.16385                  
    ddraw.dll                  6.1.7600.16385              Microsoft DirectDraw
    ddrawex.dll                6.1.7600.16385              Direct Draw Ex
    defaultlocationcpl.dll     6.1.7600.16385               :   
    deployjava1.dll            6.0.290.11                  Java(TM) Platform SE binary
    deskadp.dll                6.1.7600.16385                 
    deskmon.dll                6.1.7600.16385                
    deskperf.dll               6.1.7600.16385                
    devenum.dll                6.6.7600.16385               .
    devicecenter.dll           6.1.7600.16385                
    devicedisplaystatusmanager.dll  6.1.7600.16385              Device Display Status Manager
    devicemetadataparsers.dll  6.1.7600.16385              Common Device Metadata parsers
    devicepairing.dll          6.1.7600.16385               ,   
    devicepairingfolder.dll    6.1.7600.16385                 
    devicepairinghandler.dll   6.1.7600.16385              Device Pairing Handler Dll
    devicepairingproxy.dll     6.1.7600.16385              Device Pairing Proxy Dll
    deviceuxres.dll            6.1.7600.16385              Windows Device User Experience Resource File
    devmgr.dll                 6.1.7600.16385                 
    devobj.dll                 6.1.7600.16820              Device Information Set DLL
    devrtl.dll                 6.1.7600.16820              Device Management Run Time Library
    dfscli.dll                 6.1.7600.16385              Windows NT Distributed File System Client DLL
    dfshim.dll                 4.0.31106.0                     ClickOnce
    dfsshlex.dll               6.1.7600.16385                   DFS
    dhcpcmonitor.dll           6.1.7600.16385               (DLL)   DHCP
    dhcpcore.dll               6.1.7600.16385               DHCP-
    dhcpcore6.dll              6.1.7600.16385               DHCPv6
    dhcpcsvc.dll               6.1.7600.16385               DHCP-
    dhcpcsvc6.dll              6.1.7600.16385               DHCPv6
    dhcpqec.dll                6.1.7600.16385                   Microsoft DHCP
    dhcpsapi.dll               6.1.7600.16385               API  DHCP-c
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                6.1.7600.16385               DLL  DIMS
    dimsroam.dll               6.1.7600.16385               DLL  DIMS  
    dinput.dll                 6.1.7600.16385              Microsoft DirectInput
    dinput8.dll                6.1.7600.16385              Microsoft DirectInput
    directdb.dll               6.1.7600.16385              Microsoft Direct Database API
    diskcopy.dll               6.1.7600.16385              Windows DiskCopy
    dispex.dll                 5.8.7600.16385              Microsoft  DispEx
    display.dll                6.1.7600.16385                
    dmband.dll                 6.1.7600.16385              Microsoft DirectMusic Band
    dmcompos.dll               6.1.7600.16385              Microsoft DirectMusic Composer
    dmdlgs.dll                 6.1.7600.16385              Disk Management Snap-in Dialogs
    dmdskmgr.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dmdskres.dll               6.1.7600.16385                 
    dmdskres2.dll              6.1.7600.16385                 
    dmime.dll                  6.1.7600.16385              Microsoft DirectMusic Interactive Engine
    dmintf.dll                 6.1.7600.16385              Disk Management DCOM Interface Stub
    dmloader.dll               6.1.7600.16385              Microsoft DirectMusic Loader
    dmocx.dll                  6.1.7600.16385              TreeView OCX
    dmrc.dll                   6.1.7600.16385              Windows MRC
    dmscript.dll               6.1.7600.16385              Microsoft DirectMusic Scripting
    dmstyle.dll                6.1.7600.16385              Microsoft DirectMusic Style Engline
    dmsynth.dll                6.1.7600.16385              Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 6.1.7600.16385                Microsoft DirectMusic
    dmutil.dll                 6.1.7600.16385                 
    dmvdsitf.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dnsapi.dll                 6.1.7600.16772                API DNS-
    dnscmmc.dll                6.1.7600.16385               DLL  DNS  MMC
    docprop.dll                6.1.7600.16385                OLE
    dot3api.dll                6.1.7600.16385              802.3 Autoconfiguration API
    dot3cfg.dll                6.1.7600.16385               Netsh  802.3
    dot3dlg.dll                6.1.7600.16385                UI  802.3
    dot3gpclnt.dll             6.1.7600.16385                   802.3
    dot3gpui.dll               6.1.7600.16385               "   802.3"
    dot3hc.dll                 6.1.7600.16385                 Dot3
    dot3msm.dll                6.1.7600.16385                   802.3
    dot3ui.dll                 6.1.7600.16385                802.3
    dpapiprovider.dll          6.1.7600.16385               DLL dpapiprovider
    dplayx.dll                 6.1.7600.16385              Microsoft DirectPlay
    dpmodemx.dll               6.1.7600.16385                      DirectPlay
    dpnaddr.dll                6.1.7600.16385              Microsoft DirectPlay8 Address
    dpnathlp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPnP
    dpnet.dll                  6.1.7600.16385              Microsoft DirectPlay
    dpnhpast.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPNP
    dpnlobby.dll               6.1.7600.16385              Microsoft DirectPlay8 Lobby
    dpwsockx.dll               6.1.7600.16385                  TCP/IP  IPX  DirectPlay
    dpx.dll                    6.1.7600.16385              Microsoft(R) Delta Package Expander
    drmmgrtn.dll               11.0.7600.16385             DRM Migration DLL
    drmv2clt.dll               11.0.7600.16385             DRMv2 Client DLL
    drprov.dll                 6.1.7600.16385                   ,        ()
    drt.dll                    6.1.7600.16385                
    drtprov.dll                6.1.7600.16385              Distributed Routing Table Providers
    drttransport.dll           6.1.7600.16385              Distributed Routing Table Transport Provider
    drvstore.dll               6.1.7600.16385              Driver Store API
    ds32gt.dll                 6.1.7600.16385              ODBC Driver Setup Generic Thunk
    dsauth.dll                 6.1.7600.16385              DS Authorization for Services
    dsdmo.dll                  6.1.7600.16385              DirectSound Effects
    dshowrdpfilter.dll         1.0.0.0                           ()
    dskquota.dll               6.1.7600.16385               DLL    Windows
    dskquoui.dll               6.1.7600.16385               DLL   
    dsound.dll                 6.1.7600.16385              DirectSound
    dsprop.dll                 6.1.7600.16385                Active Directory
    dsquery.dll                6.1.7600.16385                 
    dsrole.dll                 6.1.7600.16385              DS Role Client DLL
    dssec.dll                  6.1.7600.16385                 
    dssenh.dll                 6.1.7600.16385              Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsuiext.dll                6.1.7600.16385                 
    dswave.dll                 6.1.7600.16385              Microsoft DirectMusic Wave
    dtsh.dll                   6.1.7600.16385               API     
    dui70.dll                  6.1.7600.16385               DirectUI Windows
    duser.dll                  6.1.7600.16385              Windows DirectUser Engine
    dwmapi.dll                 6.1.7600.16385               API     ()
    dwmcore.dll                6.1.7600.16385                Microsoft DWM
    dwrite.dll                 6.1.7600.16385               Microsoft DirectX Typography
    dxdiagn.dll                6.1.7600.16385                Microsoft DirectX
    dxgi.dll                   6.1.7600.16385              DirectX Graphics Infrastructure
    dxmasf.dll                 12.0.7600.16385             Microsoft Windows Media Component Removal File.
    dxptaskringtone.dll        6.1.7600.16385                 Microsoft
    dxptasksync.dll            6.1.7600.16385               Microsoft Windows DXP
    dxtmsft.dll                8.0.7600.16385              DirectX Media -- Image DirectX Transforms
    dxtrans.dll                8.0.7600.16385              DirectX Media -- DirectX Transform Core
    dxva2.dll                  6.1.7600.16385              DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               6.1.7600.16385              Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                6.1.7600.16385                EAP
    eappgnui.dll               6.1.7600.16385                 EAP
    eapphost.dll               6.1.7600.16385                 EAPHost 
    eappprxy.dll               6.1.7600.16385              Microsoft EAPHost Peer Client DLL
    eapqec.dll                 6.1.7600.16385                   Microsoft EAP
    efsadu.dll                 6.1.7600.16385                
    efscore.dll                6.1.7600.16385              EFS Core Library
    efsutil.dll                6.1.7600.16385              EFS Utility Library
    ehstorapi.dll              6.1.7600.16385              Windows Enhanced Storage API
    ehstorpwdmgr.dll           6.1.7600.16385                Windows Enhanced Storage
    ehstorshell.dll            6.1.7600.16385               DLL   Windows Enhanced Storage
    els.dll                    6.1.7600.16385                
    elscore.dll                6.1.7600.16385               DLL   Els
    elslad.dll                 6.1.7600.16385              ELS Language Detection
    elstrans.dll               6.1.7600.16385              ELS Transliteration Service
    encapi.dll                 6.1.7600.16385              Encoder API
    encdec.dll                 6.6.7600.16724                XDS     .
    eqossnap.dll               6.1.7600.16385                EQoS
    es.dll                     2001.12.8530.16385          COM+
    esent.dll                  6.1.7600.16385                  ESE  Microsoft(R) Windows(R)
    esentprf.dll               6.1.7600.16385              Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    eventcls.dll               6.1.7600.16385              Microsoft Volume Shadow Copy Service event class
    evr.dll                    6.1.7600.16385                DLL   
    explorerframe.dll          6.1.7600.16385              ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    f3ahvoas.dll               6.1.7600.16385              JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               6.1.7600.16385                     Windows
    fdbth.dll                  6.1.7600.16385              Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             6.1.7600.16385              Bluetooth Provider Proxy Dll
    fde.dll                    6.1.7600.16385                 
    fdeploy.dll                6.1.7600.16385                  
    fdpnp.dll                  6.1.7600.16385              Pnp Provider Dll
    fdproxy.dll                6.1.7600.16385              Function Discovery Proxy Dll
    fdssdp.dll                 6.1.7600.16385              Function Discovery SSDP Provider Dll
    fdwcn.dll                  6.1.7600.16385              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 6.1.7600.16385              Function Discovery WNet Provider Dll
    fdwsd.dll                  6.1.7600.16385              Function Discovery WS Discovery Provider Dll
    feclient.dll               6.1.7600.16385              Windows NT File Encryption Client Interfaces
    ff_vfw.dll                                             
    filemgmt.dll               6.1.7600.16385                 
    findnetprinters.dll        6.1.7600.16385              Find Network Printers COM Component
    firewallapi.dll            6.1.7600.16385              API  Windows
    firewallcontrolpanel.dll   6.1.7600.16385                -  Windows
    fltlib.dll                 6.1.7600.16385               
    fm20enu.dll                12.0.4518.1010              Microsoft Forms International DLL
    fmifs.dll                  6.1.7600.16385              FM IFS Utility DLL
    fms.dll                    1.1.6000.16384                
    fontext.dll                6.1.7600.16385                Windows
    fontsub.dll                6.1.7600.16444              Font Subsetting DLL
    fphc.dll                   6.1.7600.16385               Filtering Platform Helper
    framedyn.dll               6.1.7600.16385              WMI SDK Provider Framework
    framedynos.dll             6.1.7600.16385              WMI SDK Provider Framework
    frapsvid.dll               3.2.3.11797                 Fraps
    fthsvc.dll                 6.1.7600.16385                  Microsoft Windows
    fundisc.dll                6.1.7600.16385              DLL  
    fwcfg.dll                  6.1.7600.16385                  Windows
    fwpuclnt.dll               6.1.7600.16385              API   FWP/IPsec
    fwremotesvr.dll            6.1.7600.16385              Windows Firewall Remote APIs Server
    fxsapi.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    fxscom.dll                 6.1.7600.16385              Microsoft Fax Server COM Client Interface
    fxscomex.dll               6.1.7600.16385              Microsoft Fax Server Extended COM Client Interface
    fxsext32.dll               6.1.7600.16385              Microsoft  Fax Exchange Command Extension
    fxsresm.dll                6.1.7600.16385               DLL   (Microsoft)
    fxsxp32.dll                6.1.7600.16385              Microsoft  Fax Transport Provider
    gameux.dll                 6.1.7600.16385               
    gameuxlegacygdfs.dll       1.0.0.1                     Legacy GDF resource DLL
    gcdef.dll                  6.1.7600.16385                   
    gdi32.dll                  6.1.7600.16385              GDI Client DLL
    getuname.dll               6.1.7600.16385                   UCE
    glmf32.dll                 6.1.7600.16385              OpenGL Metafiling DLL
    glu32.dll                  6.1.7600.16385                OpenGL
    gpapi.dll                  6.1.7600.16385                API  
    gpedit.dll                 6.1.7600.16385              GPEdit
    gpprefcl.dll               6.1.7600.16385                 
    gpprnext.dll               6.1.7600.16385                 
    gpscript.dll               6.1.7600.16385                
    gptext.dll                 6.1.7600.16385              GPTExt
    hbaapi.dll                 6.1.7600.16385              HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            6.1.7600.16385                
    helppaneproxy.dll          6.1.7600.16385              Microsoft Help Proxy
    hgcpl.dll                  6.1.7600.16385                 
    hhsetup.dll                6.1.7600.16385              Microsoft HTML Help
    hid.dll                    6.1.7600.16385                HID
    hidserv.dll                6.1.7600.16385               HID
    hlink.dll                  6.1.7600.16385               Microsoft Office 2000
    hnetcfg.dll                6.1.7600.16385                 
    hnetmon.dll                6.1.7600.16385              DLL   
    httpapi.dll                6.1.7600.16385              HTTP Protocol Stack API
    htui.dll                   6.1.7600.16385                  
    ias.dll                    6.1.7600.16385                 (NPS)
    iasacct.dll                6.1.7600.16385                NPS
    iasads.dll                 6.1.7600.16385                Active Directory NPS
    iasdatastore.dll           6.1.7600.16385              NPS Datastore server
    iashlpr.dll                6.1.7600.16385                NPS
    iasmigplugin.dll           6.1.7600.16385              NPS Migration DLL
    iasnap.dll                 6.1.7600.16385              NPS NAP Provider
    iaspolcy.dll               6.1.7600.16385              NPS Pipeline
    iasrad.dll                 6.1.7600.16385                RADIUS NPS
    iasrecst.dll               6.1.7600.16385              NPS XML Datastore Access
    iassam.dll                 6.1.7600.16385              NPS NT SAM Provider
    iassdo.dll                 6.1.7600.16385               SDO NPS
    iassvcs.dll                6.1.7600.16385                NPS
    icardie.dll                8.0.7600.16385              Microsoft Information Card IE Helper
    icardres.dll               3.0.4506.4926               Windows CardSpace
    iccvid.dll                 1.10.0.13                    Cinepak
    icm32.dll                  6.1.7600.16385              Microsoft Color Management Module (CMM)
    icmp.dll                   6.1.7600.16385              ICMP DLL
    icmui.dll                  6.1.7600.16385                  
    iconcodecservice.dll       6.1.7600.16385              Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 6.1.7600.16385                 
    idndl.dll                  6.1.7600.16385              Downlevel DLL
    idstore.dll                6.1.7600.16385              Identity Store
    ieakeng.dll                8.0.7600.16385                  Internet Explorer
    ieaksie.dll                8.0.7600.16385                 Internet Explorer   
    ieakui.dll                 8.0.7600.16385                UI DLL Microsoft IEAK
    ieapfltr.dll               8.0.6001.18669              Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.7600.16839               IEAK
    ieframe.dll                8.0.7600.16839              -
    iepeers.dll                8.0.7600.16839              Peer- Internet Explorer
    iernonce.dll               8.0.7600.16385                RunOnce   
    iertutil.dll               8.0.7600.16839              Run time utility for Internet Explorer
    iesetup.dll                8.0.7600.16385                IOD
    iesysprep.dll              8.0.7600.16385              IE Sysprep Provider
    ieui.dll                   8.0.7600.16839                 Internet Explorer
    ifmon.dll                  6.1.7600.16385                IF
    ifsutil.dll                6.1.7600.16385              IFS Utility DLL
    ifsutilx.dll               6.1.7600.16385              IFS Utility Extension DLL
    imagehlp.dll               6.1.7600.16385              Windows NT Image Helper
    imageres.dll               6.1.7600.16385              Windows Image Resource
    imagesp1.dll               6.1.7600.16385              Windows SP1 Image Resource
    imapi.dll                  6.1.7600.16385               Image Mastering API
    imapi2.dll                 6.1.7600.16385              IMAPI  2
    imapi2fs.dll               6.1.7600.16385              Image Mastering File System Imaging API v2
    imgutil.dll                8.0.7600.16385              IE plugin image decoder support DLL
    imjp10k.dll                10.1.7600.16385             Microsoft IME
    imm32.dll                  6.1.7600.16385              Multi-User Windows IMM32 API Client DLL
    inetcomm.dll               6.1.7600.16807              Microsoft Internet Messaging API Resources
    inetmib1.dll               6.1.7600.16385              Microsoft MIB-II subagent
    inetres.dll                6.1.7600.16385               API  
    infocardapi.dll            3.0.4506.4926               Microsoft InfoCards
    inked.dll                  6.1.7600.16385              Microsoft Tablet PC InkEdit Control
    input.dll                  6.1.7600.16385               DLL  
    inseng.dll                 8.0.7600.16385               
    iologmsg.dll               6.1.7600.16385                /
    ipbusenumproxy.dll         6.1.7600.16385              Associated Device Presence Proxy Dll
    iphlpapi.dll               6.1.7600.16385              IP Helper API
    iprop.dll                  6.1.7600.16385              OLE PropertySet Implementation
    iprtprio.dll               6.1.7600.16385              IP Routing Protocol Priority DLL
    iprtrmgr.dll               6.1.7600.16385               IP-
    ipsecsnp.dll               6.1.7600.16385                 IP-
    ipsmsnap.dll               6.1.7600.16385                IP-
    ir32_32.dll                3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_qc.dll                4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    irclass.dll                6.1.7600.16385                 
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               6.1.7600.16385              API-  iSCSI
    iscsied.dll                6.1.7600.16385              iSCSI Extension DLL
    iscsium.dll                6.1.7600.16385              iSCSI Discovery api
    iscsiwmi.dll               6.1.7600.16385              MS iSCSI Initiator WMI Provider
    itircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    itss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    itvdata.dll                6.6.7600.16385              iTV Data Filters.
    iyuv_32.dll                6.1.7600.16490              Intel Indeo(R) Video YUV 
    jscript.dll                5.8.7600.16762              Microsoft (R) JScript
    jsproxy.dll                8.0.7600.16839              JScript Proxy Auto-Configuration
    kbd101.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 101
    kbd101a.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout for 103
    kbd106.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbd106n.dll                6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbda1.dll                  6.1.7600.16385              Arabic_English_101 Keyboard Layout
    kbda2.dll                  6.1.7600.16385              Arabic_2 Keyboard Layout
    kbda3.dll                  6.1.7600.16385              Arabic_French_102 Keyboard Layout
    kbdal.dll                  6.1.7600.16385              Albania Keyboard Layout
    kbdarme.dll                6.1.7600.16385              Eastern Armenian Keyboard Layout
    kbdarmw.dll                6.1.7600.16385              Western Armenian Keyboard Layout
    kbdax2.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 6.1.7600.16385              Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                6.1.7600.16385              Azeri-Latin Keyboard Layout
    kbdbash.dll                6.1.7600.16385              Bashkir Keyboard Layout
    kbdbe.dll                  6.1.7600.16385              Belgian Keyboard Layout
    kbdbene.dll                6.1.7600.16385              Belgian Dutch Keyboard Layout
    kbdbgph.dll                6.1.7600.16385              Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               6.1.7600.16385              Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 6.1.7600.16385              Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 6.1.7600.16385              Belarusian Keyboard Layout
    kbdbr.dll                  6.1.7600.16385              Brazilian Keyboard Layout
    kbdbu.dll                  6.1.7600.16385              Bulgarian (Typewriter) Keyboard Layout
    kbdbulg.dll                6.1.7600.16385              Bulgarian Keyboard Layout
    kbdca.dll                  6.1.7600.16385              Canadian Multilingual Keyboard Layout
    kbdcan.dll                 6.1.7600.16385              Canadian Multilingual Standard Keyboard Layout
    kbdcr.dll                  6.1.7600.16385              Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  6.1.7600.16385              Czech Keyboard Layout
    kbdcz1.dll                 6.1.7600.16385              Czech_101 Keyboard Layout
    kbdcz2.dll                 6.1.7600.16385              Czech_Programmer's Keyboard Layout
    kbdda.dll                  6.1.7600.16385              Danish Keyboard Layout
    kbddiv1.dll                6.1.7600.16385              Divehi Phonetic Keyboard Layout
    kbddiv2.dll                6.1.7600.16385              Divehi Typewriter Keyboard Layout
    kbddv.dll                  6.1.7600.16385              Dvorak US English Keyboard Layout
    kbdes.dll                  6.1.7600.16385              Spanish Alernate Keyboard Layout
    kbdest.dll                 6.1.7600.16385              Estonia Keyboard Layout
    kbdfa.dll                  6.1.7600.16385              Persian Keyboard Layout
    kbdfc.dll                  6.1.7600.16385              Canadian French Keyboard Layout
    kbdfi.dll                  6.1.7600.16385              Finnish Keyboard Layout
    kbdfi1.dll                 6.1.7600.16385              Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  6.1.7600.16385              F?roese Keyboard Layout
    kbdfr.dll                  6.1.7600.16385              French Keyboard Layout
    kbdgae.dll                 6.1.7600.16385              Gaelic Keyboard Layout
    kbdgeo.dll                 6.1.7600.16385              Georgian Keyboard Layout
    kbdgeoer.dll               6.1.7600.16385              Georgian (Ergonomic) Keyboard Layout
    kbdgeoqw.dll               6.1.7600.16385              Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 6.1.7600.16385              Greek_Latin Keyboard Layout
    kbdgr.dll                  6.1.7600.16385              German Keyboard Layout
    kbdgr1.dll                 6.1.7600.16385              German_IBM Keyboard Layout
    kbdgrlnd.dll               6.1.7600.16385              Greenlandic Keyboard Layout
    kbdhau.dll                 6.1.7600.16385              Hausa Keyboard Layout
    kbdhe.dll                  6.1.7600.16385              Greek Keyboard Layout
    kbdhe220.dll               6.1.7600.16385              Greek IBM 220 Keyboard Layout
    kbdhe319.dll               6.1.7600.16385              Greek IBM 319 Keyboard Layout
    kbdheb.dll                 6.1.7600.16385              KBDHEB Keyboard Layout
    kbdhela2.dll               6.1.7600.16385              Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               6.1.7600.16385              Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                6.1.7600.16385              Greek_Polytonic Keyboard Layout
    kbdhu.dll                  6.1.7600.16385              Hungarian Keyboard Layout
    kbdhu1.dll                 6.1.7600.16385              Hungarian 101-key Keyboard Layout
    kbdibm02.dll               6.1.7600.16385              JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 6.1.7600.16385              Igbo Keyboard Layout
    kbdic.dll                  6.1.7600.16385              Icelandic Keyboard Layout
    kbdinasa.dll               6.1.7600.16385              Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               6.1.7600.16385              Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               6.1.7600.16385              Bengali (Inscript) Keyboard Layout
    kbdinben.dll               6.1.7600.16385              Bengali Keyboard Layout
    kbdindev.dll               6.1.7600.16385              Devanagari Keyboard Layout
    kbdinguj.dll               6.1.7600.16385              Gujarati Keyboard Layout
    kbdinhin.dll               6.1.7600.16385              Hindi Keyboard Layout
    kbdinkan.dll               6.1.7600.16385              Kannada Keyboard Layout
    kbdinmal.dll               6.1.7600.16385              Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               6.1.7600.16385              Marathi Keyboard Layout
    kbdinori.dll               6.1.7600.16385              Oriya Keyboard Layout
    kbdinpun.dll               6.1.7600.16385              Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               6.1.7600.16385              Tamil Keyboard Layout
    kbdintel.dll               6.1.7600.16385              Telugu Keyboard Layout
    kbdinuk2.dll               6.1.7600.16385              Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  6.1.7600.16385              Irish Keyboard Layout
    kbdit.dll                  6.1.7600.16385              Italian Keyboard Layout
    kbdit142.dll               6.1.7600.16385              Italian 142 Keyboard Layout
    kbdiulat.dll               6.1.7600.16385              Inuktitut Latin Keyboard Layout
    kbdjpn.dll                 6.1.7600.16385              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 6.1.7600.16385              Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                6.1.7600.16385              Cambodian Standard Keyboard Layout
    kbdkor.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout Stub driver
    kbdkyr.dll                 6.1.7600.16385              Kyrgyz Keyboard Layout
    kbdla.dll                  6.1.7600.16385              Latin-American Spanish Keyboard Layout
    kbdlao.dll                 6.1.7600.16385              Lao Standard Keyboard Layout
    kbdlk41a.dll               6.1.7600.16385              DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  6.1.7600.16385              Lithuania Keyboard Layout
    kbdlt1.dll                 6.1.7600.16385              Lithuanian Keyboard Layout
    kbdlt2.dll                 6.1.7600.16385              Lithuanian Standard Keyboard Layout
    kbdlv.dll                  6.1.7600.16385              Latvia Keyboard Layout
    kbdlv1.dll                 6.1.7600.16385              Latvia-QWERTY Keyboard Layout
    kbdmac.dll                 6.1.7600.16385              Macedonian (FYROM) Keyboard Layout
    kbdmacst.dll               6.1.7600.16385              Macedonian (FYROM) - Standard Keyboard Layout
    kbdmaori.dll               6.1.7600.16385              Maori Keyboard Layout
    kbdmlt47.dll               6.1.7600.16385              Maltese 47-key Keyboard Layout
    kbdmlt48.dll               6.1.7600.16385              Maltese 48-key Keyboard Layout
    kbdmon.dll                 6.1.7600.16385              Mongolian Keyboard Layout
    kbdmonmo.dll               6.1.7600.16385              Mongolian (Mongolian Script) Keyboard Layout
    kbdne.dll                  6.1.7600.16385              Dutch Keyboard Layout
    kbdnec.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               6.1.7600.16385              JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                6.1.7600.16385              Nepali Keyboard Layout
    kbdno.dll                  6.1.7600.16385              Norwegian Keyboard Layout
    kbdno1.dll                 6.1.7600.16385              Norwegian with Sami Keyboard Layout
    kbdnso.dll                 6.1.7600.16385              Sesotho sa Leboa Keyboard Layout
    kbdpash.dll                6.1.7600.16385              Pashto (Afghanistan) Keyboard Layout
    kbdpl.dll                  6.1.7600.16385              Polish Keyboard Layout
    kbdpl1.dll                 6.1.7600.16385              Polish Programmer's Keyboard Layout
    kbdpo.dll                  6.1.7600.16385              Portuguese Keyboard Layout
    kbdro.dll                  6.1.7600.16385              Romanian (Legacy) Keyboard Layout
    kbdropr.dll                6.1.7600.16385              Romanian (Programmers) Keyboard Layout
    kbdrost.dll                6.1.7600.16385              Romanian (Standard) Keyboard Layout
    kbdru.dll                  6.1.7600.16385              Russian Keyboard Layout
    kbdru1.dll                 6.1.7600.16385              Russia(Typewriter) Keyboard Layout
    kbdsf.dll                  6.1.7600.16385              Swiss French Keyboard Layout
    kbdsg.dll                  6.1.7600.16385              Swiss German Keyboard Layout
    kbdsl.dll                  6.1.7600.16385              Slovak Keyboard Layout
    kbdsl1.dll                 6.1.7600.16385              Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               6.1.7600.16385              Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               6.1.7600.16385              Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 6.1.7600.16385              Sinhala Keyboard Layout
    kbdsorex.dll               6.1.7600.16385              Sorbian Extended Keyboard Layout
    kbdsors1.dll               6.1.7600.16385              Sorbian Standard Keyboard Layout
    kbdsorst.dll               6.1.7600.16385              Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  6.1.7600.16385              Spanish Keyboard Layout
    kbdsw.dll                  6.1.7600.16385              Swedish Keyboard Layout
    kbdsw09.dll                6.1.7600.16385              Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                6.1.7600.16385              Syriac Standard Keyboard Layout
    kbdsyr2.dll                6.1.7600.16385              Syriac Phoenetic Keyboard Layout
    kbdtajik.dll               6.1.7600.16385              Tajik Keyboard Layout
    kbdtat.dll                 6.1.7600.16385              Tatar_Cyrillic Keyboard Layout
    kbdth0.dll                 6.1.7600.16385              Thai Kedmanee Keyboard Layout
    kbdth1.dll                 6.1.7600.16385              Thai Pattachote Keyboard Layout
    kbdth2.dll                 6.1.7600.16385              Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 6.1.7600.16385              Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtiprc.dll               6.1.7600.16385              Tibetan (PRC) Keyboard Layout
    kbdtuf.dll                 6.1.7600.16385              Turkish F Keyboard Layout
    kbdtuq.dll                 6.1.7600.16385              Turkish Q Keyboard Layout
    kbdturme.dll               6.1.7600.16385              Turkmen Keyboard Layout
    kbdughr.dll                6.1.7600.16385              Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               6.1.7600.16385              Uyghur Keyboard Layout
    kbduk.dll                  6.1.7600.16385              United Kingdom Keyboard Layout
    kbdukx.dll                 6.1.7600.16385              United Kingdom Extended Keyboard Layout
    kbdur.dll                  6.1.7600.16385              Ukrainian Keyboard Layout
    kbdur1.dll                 6.1.7600.16385              Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                6.1.7600.16385              Urdu Keyboard Layout
    kbdus.dll                  6.1.7600.16385              United States Keyboard Layout
    kbdusa.dll                 6.1.7600.16385              US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 6.1.7600.16385              Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 6.1.7600.16385              Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 6.1.7600.16385              US Multinational Keyboard Layout
    kbduzb.dll                 6.1.7600.16385              Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                6.1.7600.16385              Vietnamese Keyboard Layout
    kbdwol.dll                 6.1.7600.16385              Wolof Keyboard Layout
    kbdyak.dll                 6.1.7600.16385              Yakut - Russia Keyboard Layout
    kbdyba.dll                 6.1.7600.16385              Yoruba Keyboard Layout
    kbdycc.dll                 6.1.7600.16385              Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 6.1.7600.16385              Serbian (Latin) Keyboard Layout
    kerberos.dll               6.1.7600.16722                Kerberos
    kernel32.dll               6.1.7600.16850                Windows NT BASE API
    kernelbase.dll             6.1.7600.16850                Windows NT BASE API
    keyiso.dll                 6.1.7600.16385                 CNG
    keymgr.dll                 6.1.7600.16385                  
    korwbrkr.dll               6.1.7600.16385              korwbrkr
    ksuser.dll                 6.1.7600.16385              User CSA Library
    ktmw32.dll                 6.1.7600.16385              Windows KTM Win32 Client DLL
    l2gpstore.dll              6.1.7600.16385              Policy Storage dll
    l2nacp.dll                 6.1.7600.16385                 Onex Windows
    l2sechc.dll                6.1.7600.16385                    2
    laprxy.dll                 12.0.7600.16385             Windows Media Logagent Proxy
    licmgr10.dll               8.0.7600.16839               (DLL)    Microsoft
    linkinfo.dll               6.1.7600.16385              Windows Volume Tracking
    livessp.dll                6.500.3165.0                LiveSSP
    loadperf.dll               6.1.7600.16385                  
    localsec.dll               6.1.7600.16385               MMC "   "
    locationapi.dll            6.1.7600.16385              Microsoft Windows Location API
    loghours.dll               6.1.7600.16385               
    logoncli.dll               6.1.7600.16385              Net Logon Client DLL
    lpk.dll                    6.1.7600.16385              Language Pack
    lsmproxy.dll               6.1.7600.16385              LSM interfaces proxy Dll
    luainstall.dll             6.1.7600.16385              Lua manifest install
    lz32.dll                   6.1.7600.16385              LZ Expand/Compress API DLL
    magnification.dll          6.1.7600.16385               API  ()
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    mcapo32.dll                1.0.18.0                    Creative Audio Processing Object Module
    mcewmdrmndbootstrap.dll    1.3.2297.0                  Windows Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
    mciavi32.dll               6.1.7600.16490               MCI Video  Windows
    mcicda.dll                 6.1.7600.16385               MCI   cdaudio
    mciqtz32.dll               6.6.7600.16385               MCI DirectShow
    mciseq.dll                 6.1.7600.16385               MCI   MIDI
    mciwave.dll                6.1.7600.16385               MCI   
    mctres.dll                 6.1.7600.16385                MCT
    mdminst.dll                6.1.7600.16385               
    mediametadatahandler.dll   6.1.7600.16385              Media Metadata Handler
    mf.dll                     12.0.7600.16385               
    mf3216.dll                 6.1.7600.16385              32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               6.1.7600.16385              Media Foundation AAC Encoder
    mfc100.dll                 10.0.30319.415              MFCDLL Shared Library - Retail Version
    mfc100chs.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100cht.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100deu.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100enu.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100esn.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100fra.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100ita.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100jpn.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100kor.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100rus.dll              10.0.30319.415              MFC Language Specific Resources
    mfc100u.dll                10.0.30319.415              MFCDLL Shared Library - Retail Version
    mfc40.dll                  4.1.0.6151                    MFCDLL -  
    mfc40u.dll                 4.1.0.6151                    MFCDLL -  
    mfc42.dll                  6.6.8064.0                    MFCDLL -  
    mfc42u.dll                 6.6.8064.0                    MFCDLL -  
    mfcm100.dll                10.0.30319.415              MFC Managed Library - Retail Version
    mfcm100u.dll               10.0.30319.415              MFC Managed Library - Retail Version
    mfcsubs.dll                2001.12.8530.16385          COM+
    mfds.dll                   12.0.7600.16385             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                6.1.7600.16385              Media Foundation DV Decoder
    mferror.dll                12.0.7600.16385                
    mfh264enc.dll              6.1.7600.16385              Media Foundation H264 Encoder
    mfmjpegdec.dll             6.1.7600.16385              Media Foundation MJPEG Decoder
    mfplat.dll                 12.0.7600.16385             Media Foundation Platform DLL
    mfplay.dll                 12.0.7600.16385             Media Foundation Playback API DLL
    mfps.dll                   12.0.7600.16385             Media Foundation Proxy DLL
    mfreadwrite.dll            12.0.7600.16385             Media Foundation ReadWrite DLL
    mfvdsp.dll                 6.1.7600.16385              Windows Media Foundation Video DSP Components
    mfwmaaec.dll               6.1.7600.16385              Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                6.1.7600.16385              Microsoft SNMP Manager API (uses WinSNMP)
    midimap.dll                6.1.7600.16385              Microsoft MIDI Mapper
    migisol.dll                6.1.7600.16385              Migration System Isolation Layer
    miguiresource.dll          6.1.7600.16385               MIG wini32
    mimefilt.dll               2008.0.7600.16385            MIME
    mlang.dll                  6.1.7600.16385               DLL  
    mmcbase.dll                6.1.7600.16385                DLL MMC
    mmci.dll                   6.1.7600.16385                
    mmcico.dll                 6.1.7600.16385              Media class co-installer
    mmcndmgr.dll               6.1.7600.16385                 MMC
    mmcshext.dll               6.1.7600.16385              MMC Shell Extension DLL
    mmdevapi.dll               6.1.7600.16385              MMDevice API
    mmres.dll                  6.1.7600.16385               
    modemui.dll                6.1.7600.16385                Windows
    moricons.dll               6.1.7600.16385              Windows NT Setup Icon Resources Library
    mp3dmod.dll                6.1.7600.16385              Microsoft MP3 Decoder DMO
    mp43decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               6.1.7600.16385              Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mpr.dll                    6.1.7600.16385                   
    mprapi.dll                 6.1.7600.16385              Windows NT MP Router Administration DLL
    mprddm.dll                 6.1.7600.16385                  
    mprdim.dll                 6.1.7600.16385                
    mprmsg.dll                 6.1.7600.16385               (DLL)    
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               6.1.7600.16385              Microsoft AC-3 Encoder
    msacm32.dll                6.1.7600.16385                 Microsoft
    msadce.dll                 6.1.7600.16385              OLE DB Cursor Engine
    msadcer.dll                6.1.7600.16385              OLE DB Cursor Engine Resources
    msadcf.dll                 6.1.7600.16385              Remote Data Services Data Factory
    msadcfr.dll                6.1.7600.16385              Remote Data Services Data Factory Resources
    msadco.dll                 6.1.7600.16688              Remote Data Services Data Control
    msadcor.dll                6.1.7600.16385              Remote Data Services Data Control Resources
    msadcs.dll                 6.1.7600.16385              Remote Data Services ISAPI Library
    msadds.dll                 6.1.7600.16385              OLE DB Data Shape Provider
    msaddsr.dll                6.1.7600.16385               OLE DB Data Shape Provider Resources
    msader15.dll               6.1.7600.16385              ActiveX Data Objects Resources
    msado15.dll                6.1.7600.16688              ActiveX Data Objects
    msadomd.dll                6.1.7600.16688              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               6.1.7600.16385              Microsoft ActiveX Data Objects Recordset
    msadox.dll                 6.1.7600.16688              ActiveX Data Objects Extensions
    msadrh15.dll               6.1.7600.16385              ActiveX Data Objects Rowset Helper
    msafd.dll                  6.1.7600.16385              Microsoft Windows Sockets 2.0 Service Provider
    msasn1.dll                 6.1.7600.16415              ASN.1 Runtime APIs
    msaudite.dll               6.1.7600.16385                 
    mscandui.dll               6.1.7600.16385                MSCANDUI
    mscat32.dll                6.1.7600.16385              MSCAT32 Forwarder DLL
    msclmd.dll                 6.1.7600.16385              Microsoft Class Mini-driver
    mscms.dll                  6.1.7600.16385              DLL-    
    mscoree.dll                4.0.31106.0                 Microsoft .NET Runtime Execution Engine
    mscorier.dll               2.0.50727.4927               IE    Microsoft .NET
    mscories.dll               2.0.50727.4927              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               6.1.7600.16385              ODBC Code Page Translator Resources
    mscpxl32.dll               6.1.7600.16385                 ODBC
    msctf.dll                  6.1.7600.16385                MSCTF
    msctfmonitor.dll           6.1.7600.16385              MsCtfMonitor DLL
    msctfp.dll                 6.1.7600.16385              MSCTFP Server DLL
    msctfui.dll                6.1.7600.16385                MSCTFUI
    msdadc.dll                 6.1.7600.16385              OLE DB Data Conversion Stub
    msdadiag.dll               6.1.7600.16385              Built-In Diagnostics
    msdaenum.dll               6.1.7600.16385              OLE DB Root Enumerator Stub
    msdaer.dll                 6.1.7600.16385              OLE DB Error Collection Stub
    msdaora.dll                6.1.7600.16385              OLE DB Provider for Oracle
    msdaorar.dll               6.1.7600.16385              OLE DB Provider for Oracle Resources
    msdaosp.dll                6.1.7600.16833              OLE DB Simple Provider
    msdaprsr.dll               6.1.7600.16385                OLE DB Persistence Services
    msdaprst.dll               6.1.7600.16385              OLE DB Persistence Services
    msdaps.dll                 6.1.7600.16385              OLE DB Interface Proxies/Stubs
    msdarem.dll                6.1.7600.16385              OLE DB Remote Provider
    msdaremr.dll               6.1.7600.16385              OLE DB Remote Provider Resources
    msdart.dll                 6.1.7600.16385              OLE DB Runtime Routines
    msdasc.dll                 6.1.7600.16385              OLE DB Service Components Stub
    msdasql.dll                6.1.7600.16385              OLE DB Provider for ODBC Drivers
    msdasqlr.dll               6.1.7600.16385              OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                6.1.7600.16385              OLE DB Implementation Support Routines
    msdatt.dll                 6.1.7600.16385              OLE DB Temporary Table Services
    msdaurl.dll                6.1.7600.16385              OLE DB RootBinder Stub
    msdelta.dll                6.1.7600.16385              Microsoft Patch Engine
    msdfmap.dll                6.1.7600.16385              Data Factory Handler
    msdmo.dll                  6.6.7600.16385              DMO Runtime
    msdrm.dll                  6.1.7600.16385                 Windows
    msdtcprx.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtcuiu.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.8530.16385               Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9756.0                  Microsoft Jet Excel Isam
    msfeeds.dll                8.0.7600.16839              Microsoft Feeds Manager
    msfeedsbs.dll              8.0.7600.16839                 ()
    msftedit.dll               5.41.21.2509                Rich Text Edit Control, v4.1
    mshtml.dll                 8.0.7600.16853                HTML Microsoft
    mshtmled.dll               8.0.7600.16839              Microsoft HTML Editing Component
    mshtmler.dll               8.0.7600.16385                  HTML (Microsoft)
    msi.dll                    5.0.7600.16385              Windows Installer
    msidcrl30.dll              6.1.7600.16385              IDCRL Dynamic Link Library
    msident.dll                6.1.7600.16385                (Microsoft)
    msidle.dll                 6.1.7600.16385              User Idle Monitor
    msidntld.dll               6.1.7600.16385                (Microsoft)
    msieftp.dll                6.1.7600.16385                Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.7600.16385              Windows installer
    msiltcfg.dll               5.0.7600.16385              Windows Installer Configuration API Stub
    msimg32.dll                6.1.7600.16385              GDIEXT Client DLL
    msimsg.dll                 5.0.7600.16385                 Windows
    msimtf.dll                 6.1.7600.16385              Active IMM Server DLL
    msisip.dll                 5.0.7600.16385              MSI Signature SIP Provider
    msjet40.dll                4.0.9756.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9756.0                  
    msjint40.dll               4.0.9756.0                       Microsoft Jet
    msjro.dll                  6.1.7600.16385              Jet and Replication Objects
    msjter40.dll               4.0.9756.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9756.0                  Microsoft Jet Expression Service
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9756.0                  Microsoft Jet Lotus 1-2-3 Isam
    msmpeg2adec.dll            6.1.7140.0                  Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             6.1.7600.16385               Microsoft MPEG-2
    msmpeg2vdec.dll            6.1.7140.0                  Microsoft DTV-DVD Video Decoder
    msnetobj.dll               11.0.7600.16385             DRM ActiveX Network Object
    msobjs.dll                 6.1.7600.16385                 
    msoeacct.dll               6.1.7600.16385              Microsoft Internet Account Manager
    msoert2.dll                6.1.7600.16385              Microsoft Windows Mail RT Lib
    msorc32r.dll               6.1.7600.16385                ODBC  Oracle
    msorcl32.dll               6.1.7600.16385              ODBC Driver for Oracle
    mspatcha.dll               6.1.7600.16385              Microsoft File Patch Application API
    mspbde40.dll               4.0.9756.0                  Microsoft Jet Paradox Isam
    msports.dll                6.1.7600.16385                 
    msrating.dll               8.0.7600.16385                   
    msrd2x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrdc.dll                  6.1.7600.16385              Remote Differential Compression COM server
    msrdpwebaccess.dll         6.1.7600.16385              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9756.0                  Microsoft Replication Library
    msrle32.dll                6.1.7600.16490              Microsoft RLE Compressor
    msscntrs.dll               7.0.7600.16385              msscntrs.dll
    msscp.dll                  11.0.7600.16385             Windows Media Secure Content Provider
    mssha.dll                  6.1.7600.16385                  Windows
    msshavmsg.dll              6.1.7600.16385                     Windows
    msshooks.dll               7.0.7600.16385              MSSHooks.dll
    mssign32.dll               6.1.7600.16385               API  
    mssip32.dll                6.1.7600.16385              MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.7600.16385              mssitlb
    mssph.dll                  7.0.7600.16385                 Microsoft
    mssphtb.dll                7.0.7600.16385              Outlook MSSearch Connector
    mssprxy.dll                7.0.7600.16385              Microsoft Search Proxy
    mssrch.dll                 7.0.7600.16385              mssrch.dll
    mssvp.dll                  7.0.7600.16385               Vista MSSearch
    msswch.dll                 6.1.7600.16385              msswch
    mstask.dll                 6.1.7600.16385                 
    mstext40.dll               4.0.9756.0                  Microsoft Jet Text Isam
    mstime.dll                 8.0.7600.16839              Microsoft (R) Timed Interactive Multimedia Extensions to HTML
    mstscax.dll                6.1.7600.16722              ActiveX-    
    msutb.dll                  6.1.7600.16385               (DLL)  MSUTB
    msv1_0.dll                 6.1.7600.16420              Microsoft Authentication Package v1.0
    msvbvm60.dll               6.0.98.15                   Visual Basic Virtual Machine
    msvcirt.dll                7.0.7600.16385              Windows NT IOStreams DLL
    msvcp100.dll               10.0.30319.415              Microsoft C Runtime Library
    msvcp60.dll                7.0.7600.16385              Windows NT C++ Runtime Library DLL
    msvcr100.dll               10.0.30319.415              Microsoft C Runtime Library
    msvcr100_clr0400.dll       10.0.30319.1                Microsoft C Runtime Library
    msvcr71.dll                7.10.3052.4                 Microsoft C Runtime Library
    msvcrt.dll                 7.0.7600.16385              Windows NT CRT DLL
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               6.1.7600.16385              VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                6.1.7600.16385               Microsoft Video  Windows
    msvidc32.dll               6.1.7600.16490                Microsoft Video 1
    msvidctl.dll               6.5.7600.16385               ActiveX  
    mswdat10.dll               4.0.9756.0                  Microsoft Jet Sort Tables
    mswmdm.dll                 12.0.7600.16385               Windows Media Device Manager
    mswsock.dll                6.1.7600.16385                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9756.0                    Microsoft Jet
    msxactps.dll               6.1.7600.16385              OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9756.0                  Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.7600.16605            MSXML 3.0 SP11
    msxml3r.dll                8.110.7600.16385            XML Resources
    msxml4.dll                 4.20.9876.0                 MSXML 4.0 SP 2
    msxml4r.dll                4.10.9404.0                 MSXML 4.0 SP1 Resources
    msxml6.dll                 6.30.7600.16385             MSXML 6.0 SP3
    msxml6r.dll                6.30.7600.16385             XML Resources
    msyuv.dll                  6.1.7600.16490              Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.8530.16385          COM+
    mtxex.dll                  2001.12.8530.16385          COM+
    mtxlegih.dll               2001.12.8530.16385          COM+
    mtxoci.dll                 2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           6.1.7600.16385              MUI Callback for font registry settings
    mycomput.dll               6.1.7600.16385               
    mydocs.dll                 6.1.7600.16385                 " "
    napcrypt.dll               6.1.7600.16385              NAP Cryptographic API helper
    napdsnap.dll               6.1.7600.16385               GPEdit    
    naphlpr.dll                6.1.7600.16385              NAP client config API helper
    napinsp.dll                6.1.7600.16385                    
    napipsec.dll               6.1.7600.16385                      IPSec
    napmontr.dll               6.1.7600.16385                NAP  Netsh
    nativehooks.dll            6.1.7600.16385              Microsoft Narrator Native hook handler
    naturallanguage6.dll       6.1.7600.16385              Natural Language Development Platform 6
    ncdprop.dll                6.1.7600.16385                 
    nci.dll                    6.1.7600.16385              CoInstaller: NET
    ncobjapi.dll               6.1.7600.16385              Microsoft Windows Operating System
    ncrypt.dll                 6.1.7600.16385                (Windows)
    ncryptui.dll               6.1.7600.16385               UI     Windows
    ncsi.dll                   6.1.7600.16385                 
    nddeapi.dll                6.1.7600.16385              Network DDE Share Management APIs
    ndfapi.dll                 6.1.7600.16385              API    
    ndfetw.dll                 6.1.7600.16385              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         6.1.7600.16385              Network Diagnostic Framework HC Discovery API
    ndiscapcfg.dll             6.1.7600.16385              NdisCap Notify Object
    ndishc.dll                 6.1.7600.16385                NDIS
    ndproxystub.dll            6.1.7600.16385              Network Diagnostic Engine Proxy/Stub
    negoexts.dll               6.1.7600.16385              NegoExtender Security Package
    netapi32.dll               6.1.7600.16385              Net Win32 API DLL
    netbios.dll                6.1.7600.16385              NetBIOS Interface Library
    netcenter.dll              6.1.7600.16385                 -  
    netcfgx.dll                6.1.7600.16385                
    netcorehc.dll              6.1.7600.16385                   
    netdiagfx.dll              6.1.7600.16385                
    netevent.dll               6.1.7600.16385                
    netfxperf.dll              4.0.31106.0                 Extensible Performance Counter Shim
    neth.dll                   6.1.7600.16385                 
    netid.dll                  6.1.7600.16385                  
    netiohlp.dll               6.1.7600.16385               DLL   Netio
    netjoin.dll                6.1.7600.16385              Domain Join DLL
    netlogon.dll               6.1.7600.16385                 Net Logon
    netmsg.dll                 6.1.7600.16385                
    netplwiz.dll               6.1.7600.16385                   
    netprof.dll                6.1.7600.16385                 
    netprofm.dll               6.1.7600.16385                
    netshell.dll               6.1.7600.16385                
    netutils.dll               6.1.7600.16385              Net Win32 API Helpers DLL
    networkexplorer.dll        6.1.7600.16385               
    networkitemfactory.dll     6.1.7600.16385                
    networkmap.dll             6.1.7600.16385               
    newdev.dll                 6.0.5054.0                    
    nlaapi.dll                 6.1.7600.16385              Network Location Awareness 2
    nlhtml.dll                 2008.0.7600.16385            HTML
    nlmgp.dll                  6.1.7600.16385                 
    nlmsprep.dll               6.1.7600.16385              Network List Manager Sysprep Module
    nlsbres.dll                6.1.7600.16385              NLSBuild resource DLL
    nlsdata0000.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0001.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0002.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0003.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0007.dll            6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlsdata0009.dll            6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlsdata000a.dll            6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlsdata000c.dll            6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlsdata000d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata000f.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0010.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0011.dll            6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlsdata0013.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0018.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0019.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0020.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0021.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0022.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0024.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0026.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0027.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata002a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0039.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata003e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0045.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0046.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0047.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0049.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004c.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0414.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0416.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0816.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata081a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0c1a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdl.dll                  6.1.7600.16385              Nls Downlevel DLL
    nlslexicons0001.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0002.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0003.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0007.dll        6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlslexicons0009.dll        6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlslexicons000a.dll        6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlslexicons000c.dll        6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlslexicons000d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons000f.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0010.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0011.dll        6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlslexicons0013.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0018.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0019.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0020.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0021.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0022.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0024.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0026.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0027.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons002a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0039.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons003e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0045.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0046.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0047.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0049.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004c.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0414.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0416.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0816.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons081a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0c1a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsmodels0011.dll          6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    normaliz.dll               6.1.7600.16385              Unicode Normalization DLL
    npmproxy.dll               6.1.7600.16385              Network List Manager Proxy
    nshhttp.dll                6.1.7600.16385               DLL netsh  HTTP
    nshipsec.dll               6.1.7600.16385               DLL  IPSec  Net
    nshwfp.dll                 6.1.7600.16385                  Windows  Netsh
    nsi.dll                    6.1.7600.16385              NSI User-mode interface DLL
    ntdll.dll                  6.1.7600.16695                NT
    ntdsapi.dll                6.1.7600.16385              Active Directory Domain Services API
    ntlanman.dll               6.1.7600.16385              Microsoft LAN Manager
    ntlanui2.dll               6.1.7600.16385                  
    ntmarta.dll                6.1.7600.16385               Windows NT MARTA
    ntprint.dll                6.1.7600.16385                  
    ntshrui.dll                6.1.7600.16385               ,    
    ntvdm64.dll                6.1.7600.16850              16-   NT64
    nvapi.dll                  8.17.12.8562                NVIDIA NVAPI Library, Version 285.62 
    nvcompiler.dll             8.17.12.8562                NVIDIA Compiler, Version 285.62 
    nvcuda.dll                 8.17.12.8562                NVIDIA CUDA Driver, Version 285.62 
    nvcuvenc.dll               6.14.12.8562                NVIDIA CUDA Video Encoder, Version 285.62 
    nvcuvid.dll                8.17.12.8562                NVIDIA CUDA Video Decode API, Version 285.62 
    nvd3dum.dll                8.17.12.8562                NVIDIA WDDM D3D Driver, Version 285.62 
    nvoglv32.dll               8.17.12.8562                NVIDIA Compatible OpenGL ICD
    nvwgf2um.dll               8.17.12.8562                NVIDIA D3D10 Driver, Version 285.62 
    objsel.dll                 6.1.7600.16385                
    occache.dll                8.0.7600.16385                  
    ocsetapi.dll               6.1.7600.16385              Windows Optional Component Setup API
    odbc32.dll                 6.1.7600.16688              ODBC Driver Manager
    odbc32gt.dll               6.1.7600.16385              ODBC Driver Generic Thunk
    odbcbcp.dll                6.1.7600.16385              BCP for ODBC
    odbcconf.dll               6.1.7600.16385              ODBC Driver Configuration Program
    odbccp32.dll               6.1.7600.16833              ODBC Installer
    odbccr32.dll               6.1.7600.16833              ODBC Cursor Library
    odbccu32.dll               6.1.7600.16833              ODBC Cursor Library
    odbcint.dll                6.1.7600.16385              ODBC Resources
    odbcji32.dll               6.1.7600.16385              Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               6.1.7600.16833              Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               6.1.7600.16833              ODBC Driver Manager Trace
    oddbse32.dll               6.1.7600.16385              ODBC (3.0) driver for DBase
    odexl32.dll                6.1.7600.16385              ODBC (3.0) driver for Excel
    odfox32.dll                6.1.7600.16385              ODBC (3.0) driver for FoxPro
    odpdx32.dll                6.1.7600.16385              ODBC (3.0) driver for Paradox
    odtext32.dll               6.1.7600.16385              ODBC (3.0) driver for text files
    offfilt.dll                2008.0.7600.16385            OFFICE
    ogldrv.dll                 6.1.7600.16385              MSOGL
    ole2.dll                   2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    ole2disp.dll               2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole2nls.dll                2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole32.dll                  6.1.7600.16624              Microsoft OLE   Windows
    oleacc.dll                 7.0.0.0                     Active Accessibility Core Component
    oleacchooks.dll            7.0.0.0                     Active Accessibility Event Hooks Library
    oleaccrc.dll               7.0.0.0                     Active Accessibility Resource DLL
    oleaut32.dll               6.1.7600.16722              
    olecli32.dll               6.1.7600.16385                OLE
    oledb32.dll                6.1.7600.16385              OLE DB Core Services
    oledb32r.dll               6.1.7600.16385                 OLE DB
    oledlg.dll                 6.1.7600.16385                 OLE
    oleprn.dll                 6.1.7600.16385              Oleprn DLL
    olepro32.dll               6.1.7600.16385              
    oleres.dll                 6.1.7600.16385                OLE
    olesvr32.dll               6.1.7600.16385              Object Linking and Embedding Server Library
    olethk32.dll               6.1.7600.16385              Microsoft OLE for Windows
    onex.dll                   6.1.7600.16385                IEEE 802.1X
    onexui.dll                 6.1.7600.16385                 IEEE 802.1X
    onlineidcpl.dll            6.1.7600.16385                -  
    oobefldr.dll               6.1.7600.16385                
    opcservices.dll            6.1.7600.16385              Native Code OPC Services Library
    openal32.dll               6.14.357.24                 Standard OpenAL(TM) Implementation
    opencl.dll                 1.0.0.0                     OpenCL Client DLL
    opengl32.dll               6.1.7600.16385              OpenGL Client DLL
    osbaseln.dll               6.1.7600.16385              Service Reporting API
    osuninst.dll               6.1.7600.16385              Uninstall Interface
    p2p.dll                    6.1.7600.16385                
    p2pcollab.dll              6.1.7600.16385                  
    p2pgraph.dll               6.1.7600.16385              Peer-to-Peer Graphing
    p2pnetsh.dll               6.1.7600.16385                 NetSh
    packager.dll               6.1.7600.16385               2
    panmap.dll                 6.1.7600.16385              PANOSE(tm) Font Mapper
    pautoenr.dll               6.1.7600.16385                
    pcaui.dll                  6.1.7600.16385                  
    pcwum.dll                  6.1.7600.16385              Performance Counters for Windows Native DLL
    pdh.dll                    6.1.7600.16385                  Windows
    pdhui.dll                  6.1.7600.16385                
    peerdist.dll               6.1.7600.16385                BranchCache
    peerdistsh.dll             6.1.7600.16385                BranchCache Netshell
    perfcentercpl.dll          6.1.7600.16385               
    perfctrs.dll               6.1.7600.16385               
    perfdisk.dll               6.1.7600.16385                  Windows
    perfnet.dll                6.1.7600.16385                   Windows
    perfos.dll                 6.1.7600.16385                  Windows
    perfproc.dll               6.1.7600.16385                   Windows
    perfts.dll                 6.1.7600.16385              Windows Remote Desktop Services Performance Objects
    photometadatahandler.dll   6.1.7600.16385              Photo Metadata Handler
    photowiz.dll               6.1.7600.16385                
    pid.dll                    6.1.7600.16385              Microsoft PID
    pidgenx.dll                6.1.7600.16385              Pid Generation
    pifmgr.dll                 6.1.7600.16385              Windows NT PIF Manager Icon Resources Library
    pku2u.dll                  6.1.7600.16385              Pku2u Security Package
    pla.dll                    6.1.7600.16385                 
    playsndsrv.dll             6.1.7600.16385               PlaySound
    pngfilt.dll                8.0.7600.16385              IE PNG plugin image decoder
    pnidui.dll                 6.1.7600.16385                
    pnpsetup.dll               6.1.7600.16385              Pnp installer for CMI
    pnrpnsp.dll                6.1.7600.16385                 PNRP
    polstore.dll               6.1.7600.16385              Policy Storage dll
    portabledeviceapi.dll      6.1.7600.16385               API    Windows
    portabledeviceclassextension.dll  6.1.7600.16385              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  6.1.7600.16385              Portable Device Connection API Components
    portabledevicestatus.dll   6.1.7600.16385                  Microsoft Windows
    portabledevicesyncprovider.dll  6.1.7600.16385                 Microsoft Windows
    portabledevicetypes.dll    6.1.7600.16385              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  6.1.7600.16385              PortableDevice WIA Compatibility Driver
    portabledevicewmdrm.dll    6.1.7600.16385              Windows Portable Device WMDRM Component
    pots.dll                   6.1.7600.16385               
    powercpl.dll               6.1.7600.16385                
    powrprof.dll               6.1.7600.16385              DLL     
    presentationcffrasterizernative_v0300.dll  3.0.6920.4902               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  4.0.31106.0                 Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.4902               PresentationNative_v0300.dll
    prflbmsg.dll               6.1.7600.16385                  
    printui.dll                6.1.7600.16385                 
    prncache.dll               6.1.7600.16385              Print UI Cache
    prnfldr.dll                6.1.7600.16385              prnfldr dll
    prnntfy.dll                6.1.7600.16385              prnntfy DLL
    prntvpt.dll                6.1.7600.16385              Print Ticket Services Module
    profapi.dll                6.1.7600.16385              User Profile Basic API
    propsys.dll                7.0.7600.16385                 (Microsoft)
    provsvc.dll                6.1.7600.16385                Windows
    provthrd.dll               6.1.7600.16385              WMI Provider Thread & Log Library
    psapi.dll                  6.1.7600.16385              Process Status Helper
    psbase.dll                 6.1.7600.16385                
    pshed.dll                  6.1.7600.16385                ,   
    psisdecd.dll               6.6.7600.16485              Microsoft SI/PSI parser for MPEG2 based networks.
    pstorec.dll                6.1.7600.16385              Protected Storage COM interfaces
    pstorsvc.dll               6.1.7600.16385              Protected storage server
    puiapi.dll                 6.1.7600.16385               DLL puiapi
    puiobj.dll                 6.1.7600.16385               DLL  PrintUI
    pwrshplugin.dll            6.1.7600.16385              pwrshplugin.dll
    qagent.dll                 6.1.7600.16385                
    qasf.dll                   12.0.7600.16385             DirectShow ASF Support
    qcap.dll                   6.6.7600.16385                DirecxX DirectShow.
    qcliprov.dll               6.1.7600.16385               WMI   
    qdv.dll                    6.6.7600.16385                DirecxX DirectShow.
    qdvd.dll                   6.6.7600.16385              DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.6.7600.16385               DirectShow
    qedwipes.dll               6.6.7600.16385              DirectShow Editing SMPTE Wipes
    qmgrprxy.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    qshvhost.dll               6.1.7600.16385                SHV
    qsvrmgmt.dll               6.1.7600.16385                
    quartz.dll                 6.6.7600.16490                DirecxX DirectShow.
    query.dll                  6.1.7600.16385                  
    qutil.dll                  6.1.7600.16385                
    qwave.dll                  6.1.7600.16385              Windows NT
    racengn.dll                6.1.7600.16385                  
    racpldlg.dll               6.1.7600.16385                 
    radardt.dll                6.1.7600.16385                   Windows
    radarrs.dll                6.1.7600.16385                   Microsoft Windows
    rasadhlp.dll               6.1.7600.16385              Remote Access AutoDial Helper
    rasapi32.dll               6.1.7600.16385              Remote Access API
    rascfg.dll                 6.1.7600.16385                RAS
    raschap.dll                6.1.7600.16385                 PPP CHAP
    rasctrs.dll                6.1.7600.16385                     Windows NT
    rasdiag.dll                6.1.7600.16385                  RAS
    rasdlg.dll                 6.1.7600.16385              API     
    rasgcw.dll                 6.1.7600.16385                RAS
    rasman.dll                 6.1.7600.16385              Remote Access Connection Manager
    rasmm.dll                  6.1.7600.16385                RAS
    rasmontr.dll               6.1.7600.16385                RAS
    rasmxs.dll                 6.1.7600.16385              Remote Access Device DLL for modems, PADs and switches
    rasplap.dll                6.1.7600.16385                 RAS PLAP
    rasppp.dll                 6.1.7600.16385              Remote Access PPP
    rasser.dll                 6.1.7600.16385              Remote Access Media DLL for COM ports
    rastapi.dll                6.1.7600.16385              Remote Access TAPI Compliance Layer
    rastls.dll                 6.1.7600.16385                 PPP EAP-TLS
    rdpcore.dll                6.1.7600.16385              RDP Core DLL
    rdpd3d.dll                 6.1.7600.16385              RDP Direct3D Remoting DLL
    rdpencom.dll               6.1.7600.16385              RDPSRAPI COM Objects
    rdpendp.dll                6.1.7600.16385                 RDP
    rdprefdrvapi.dll           6.1.7600.16385              Reflector Driver API
    reagent.dll                6.1.7600.16385               DLL   Microsoft Windows
    regapi.dll                 6.1.7600.16385              Registry Configuration APIs
    regctrl.dll                6.1.7600.16385              RegCtrl
    remotepg.dll               6.1.7600.16385              CPL-  
    resampledmo.dll            6.1.7600.16385              Windows Media Resampler
    resutils.dll               6.1.7600.16385              Microsoft Cluster Resource Utility DLL
    rgb9rast.dll               6.1.7600.16385              Microsoft Windows Operating System
    riched20.dll               5.31.23.1229                Rich Text Edit Control, v3.1
    riched32.dll               6.1.7600.16385              Wrapper Dll for Richedit 1.0
    rnr20.dll                  6.1.7600.16385              Windows Socket2 NameSpace DLL
    rpcdiag.dll                6.1.7600.16385              RPC Diagnostics
    rpchttp.dll                6.1.7600.16385              RPC HTTP DLL
    rpcndfp.dll                1.0.0.1                        RPC NDF
    rpcns4.dll                 6.1.7600.16385                    (RPC)
    rpcnsh.dll                 6.1.7600.16385                RPC Netshell
    rpcrt4.dll                 6.1.7600.16385                 
    rpcrtremote.dll            6.1.7600.16385              Remote RPC Extension
    rsaenh.dll                 6.1.7600.16385              Microsoft Enhanced Cryptographic Provider
    rshx32.dll                 6.1.7600.16385                
    rstrtmgr.dll               6.1.7600.16385               
    rtffilt.dll                2008.0.7600.16385            RTF
    rtm.dll                    6.1.7600.16385                
    rtutils.dll                6.1.7600.16617              Routing Utilities
    samcli.dll                 6.1.7600.16385              Security Accounts Manager Client DLL
    samlib.dll                 6.1.7600.16385              SAM Library DLL
    sampleres.dll              6.1.7600.16385               (Microsoft)
    sas.dll                    6.1.7600.16385              WinLogon Software SAS Library
    sbe.dll                    6.6.7600.16724              DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.7600.16385             Stream Buffer IO DLL
    sberes.dll                 6.6.7600.16385                  DirectShow.
    scansetting.dll            6.1.7600.16385                    Microsoft Windows(TM)
    scarddlg.dll               6.1.7600.16385              SCardDlg -   -
    scecli.dll                 6.1.7600.16385                 
    scesrv.dll                 6.1.7600.16385                
    schannel.dll               6.1.7600.16661              TLS / SSL Security Provider
    schedcli.dll               6.1.7600.16385              Scheduler Service Client DLL
    scksp.dll                  6.1.7600.16385              Microsoft Smart Card Key Storage Provider
    scripto.dll                6.6.7600.16385              Microsoft ScriptO
    scrobj.dll                 5.8.7600.16385              Windows  Script Component Runtime
    scrptadm.dll               6.1.7600.16385                
    scrrun.dll                 5.8.7600.16385              Microsoft  Script Runtime
    sdiageng.dll               6.1.7600.16385                 
    sdiagprv.dll               6.1.7600.16385              API    Windows
    sdohlp.dll                 6.1.7600.16385                 SDO NPS
    searchfolder.dll           6.1.7600.16385              SearchFolder
    sechost.dll                6.1.7600.16385              Host for SCM/SDDL/LSA Lookup APIs
    secproc.dll                6.1.7600.16506              Windows Rights Management Desktop Security Processor
    secproc_isv.dll            6.1.7600.16506              Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            6.1.7600.16506              Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        6.1.7600.16506              Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                6.1.7600.16484              Security Support Provider Interface
    security.dll               6.1.7600.16385              Security Support Provider Interface
    sendmail.dll               6.1.7600.16385               
    sens.dll                   6.1.7600.16385                   (SENS)
    sens_oal.dll               2.2.20.3026                 OpenAL Host Implementation
    sensapi.dll                6.1.7600.16385              SENS Connectivity API DLL
    sensorsapi.dll             6.1.7600.16385              Sensor API
    sensorscpl.dll             6.1.7600.16385                "    "
    serialui.dll               6.1.7600.16385                
    serwvdrv.dll               6.1.7600.16385                Unimodem
    sessenv.dll                6.1.7600.16385                   
    setupapi.dll               6.1.7600.16385              Windows Setup API
    setupcln.dll               6.1.7600.16385                
    sfc.dll                    6.1.7600.16385              Windows File Protection
    sfc_os.dll                 6.1.7600.16385              Windows File Protection
    shacct.dll                 6.1.7600.16385              Shell Accounts Classes
    shdocvw.dll                6.1.7600.16385                    
    shell32.dll                6.1.7600.16644                 Windows
    shellstyle.dll             6.1.7600.16385              Windows Shell Style Resource Dll
    shfolder.dll               6.1.7600.16385              Shell Folder Service
    shgina.dll                 6.1.7600.16385              Windows Shell User Logon
    shimeng.dll                6.1.7600.16385              Shim Engine DLL
    shimgvw.dll                6.1.7600.16385               
    shlwapi.dll                6.1.7600.16385                 
    shpafact.dll               6.1.7600.16385              Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                6.1.7600.16385              Shell setup helper
    shsvcs.dll                 6.1.7600.16385               DLL   Windows
    shunimpl.dll               6.1.7600.16385              Windows Shell Obsolete APIs
    shwebsvc.dll               6.1.7600.16385              -  Windows
    signdrv.dll                6.1.7600.16385              WMI provider for Signed Drivers
    sisbkup.dll                6.1.7600.16385              Single-Instance Store Backup Support Functions
    slc.dll                    6.1.7600.16385              Software Licensing Client DLL
    slcext.dll                 6.1.7600.16385              Software Licensing Client Extension Dll
    slwga.dll                  6.1.7600.16385              Software Licensing WGA API
    smartcardcredentialprovider.dll  6.1.7600.16385                 - Windows
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    sndvolsso.dll              6.1.7600.16385               SCA 
    snmpapi.dll                6.1.7600.16385              SNMP Utility Library
    softkbd.dll                6.1.7600.16385                  
    softpub.dll                6.1.7600.16385              Softpub Forwarder DLL
    sortserver2003compat.dll   6.1.7600.16385              Sort Version Server 2003
    sortwindows6compat.dll     6.1.7600.16385              Sort Version Windows 6.0
    spbcd.dll                  6.1.7600.16385              BCD Sysprep Plugin
    spfileq.dll                6.1.7600.16385              Windows SPFILEQ
    spinf.dll                  6.1.7600.16385              Windows SPINF
    spnet.dll                  6.1.7600.16385              Net Sysprep Plugin
    spopk.dll                  6.1.7600.16385              OPK Sysprep Plugin
    spp.dll                    6.1.7600.16385                  Microsoft Windows
    sppc.dll                   6.1.7600.16385              Software Licensing Client DLL
    sppcc.dll                  6.1.7600.16385                  
    sppcext.dll                6.1.7600.16385              Software Protection Platform Client Extension Dll
    sppcomapi.dll              6.1.7600.16385                 
    sppcommdlg.dll             6.1.7600.16385              API     
    sppinst.dll                6.1.7600.16385              SPP CMI Installer Plug-in DLL
    sppwmi.dll                 6.1.7600.16385              Software Protection Platform WMI provider
    spwinsat.dll               6.1.7600.16385              WinSAT Sysprep Plugin
    spwizeng.dll               6.1.7600.16385              Setup Wizard Framework
    spwizimg.dll               6.1.7600.16385              Setup Wizard Framework Resources
    spwizres.dll               6.1.7600.16385                 
    spwmp.dll                  6.1.7600.16385              Windows Media Player System Preparation DLL
    sqlceoledb30.dll           3.0.7600.0                  Microsoft SQL Mobile
    sqlceqp30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqlcese30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqloledb.dll               6.1.7600.16385              OLE DB Provider for SQL Server
    sqlsrv32.dll               6.1.7600.16385              SQL Server ODBC Driver
    sqlunirl.dll               2000.80.728.0               String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 1999.10.20.0                Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 1999.10.20.0                Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                6.1.7600.16385              XML extensions for SQL Server
    sqmapi.dll                 6.1.7600.16385              SQM Client
    srchadmin.dll              7.0.7600.16385               
    srclient.dll               6.1.7600.16385              Microsoft Windows System Restore Client Library
    srhelper.dll               6.1.7600.16385              Microsoft Windows driver and windows update enumeration library
    srpuxnativesnapin.dll      6.1.7600.16385                     
    srvcli.dll                 6.1.7600.16385              Server Service Client DLL
    sscore.dll                 6.1.7600.16664               DLL-  
    ssdpapi.dll                6.1.7600.16385              SSDP Client API DLL
    sspicli.dll                6.1.7600.16484              Security Support Provider Interface
    ssshim.dll                 6.1.7600.16385              Windows Componentization Platform Servicing API
    stclient.dll               2001.12.8530.16385          COM+ Configuration Catalog Client
    sti.dll                    6.1.7600.16385                   
    stobject.dll               6.1.7600.16385                 Systray
    storage.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    storagecontexthandler.dll  6.1.7600.16385                   
    storprop.dll               6.1.7600.16385                  
    structuredquery.dll        7.0.7600.16587              Structured Query
    sud.dll                    6.1.7600.16385                SUD
    sxproxy.dll                6.1.7600.16385                  Microsoft Windows
    sxs.dll                    6.1.7600.16385              Fusion 2.5
    sxshared.dll               6.1.7600.16385              Microsoft Windows SX Shared Library
    sxsstore.dll               6.1.7600.16385              Sxs Store DLL
    synccenter.dll             6.1.7600.16385                
    synceng.dll                6.1.7600.16385              Windows Briefcase Engine
    synchostps.dll             6.1.7600.16385              Proxystub for sync host
    syncinfrastructure.dll     6.1.7600.16385                Microsoft Windows.
    syncinfrastructureps.dll   6.1.7600.16385              Microsoft Windows sync infrastructure proxy stub.
    syncreg.dll                2007.94.7600.16385          Microsoft Synchronization Framework Registration
    syncui.dll                 6.1.7600.16385               Windows
    syssetup.dll               6.1.7600.16385              Windows NT System Setup
    systemcpl.dll              6.1.7600.16385              CPL 
    t2embed.dll                6.1.7600.16663              Microsoft T2Embed Font Embedding
    tapi3.dll                  6.1.7600.16385              Microsoft TAPI3
    tapi32.dll                 6.1.7600.16385               API  Microsoft Windows
    tapimigplugin.dll          6.1.7600.16385              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               6.1.7600.16385              Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                6.1.7600.16385                 Microsoft Windows
    tapisysprep.dll            6.1.7600.16385              Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 6.1.7600.16385               DLL   Microsoft Windows
    taskcomp.dll               6.1.7600.16699                  
    taskschd.dll               6.1.7600.16699              Task Scheduler COM API
    taskschdps.dll             6.1.7600.16385              Task Scheduler Interfaces Proxy
    tbs.dll                    6.1.7600.16385              TBS
    tcpipcfg.dll               6.1.7600.16385                
    tdh.dll                    6.1.7600.16385                 
    termmgr.dll                6.1.7600.16385              Microsoft TAPI3 Terminal Manager
    thawbrkr.dll               6.1.7600.16385              Thai Word Breaker
    themecpl.dll               6.1.7600.16385              CPL 
    themeui.dll                6.1.7600.16385              API   Windows
    thumbcache.dll             6.1.7600.16385                
    timedatemuicallback.dll    6.1.7600.16385              Time Date Control UI Language Change plugin
    tlscsp.dll                 6.1.7600.16385              Microsoft Remote Desktop Services Cryptographic Utility
    tpmcompc.dll               6.1.7600.16385                
    tquery.dll                 7.0.7600.16385              tquery.dll
    traffic.dll                6.1.7600.16385              Microsoft Traffic Control 1.0 DLL
    trapi.dll                  6.1.7600.16385              Microsoft Narrator Text Renderer
    tsbyuv.dll                 6.1.7600.16490              Toshiba Video Codec
    tschannel.dll              6.1.7600.16385              Task Scheduler Proxy
    tsgqec.dll                 6.1.7600.16385                      
    tsmf.dll                   6.1.7600.16385                MF    
    tspkg.dll                  6.1.7600.16385              Web Service Security Package
    tsworkspace.dll            6.1.7600.16385                      RemoteApp
    tvratings.dll              6.6.7600.16385              Module for managing TV ratings
    twext.dll                  6.1.7600.16385              :  
    txflog.dll                 2001.12.8530.16385          COM+
    txfw32.dll                 6.1.7600.16385              TxF Win32 DLL
    typelib.dll                2.10.3029.1                 OLE 2.1 16/32 Interoperability Library
    tzres.dll                  6.1.7600.16695               DLL   
    ubpm.dll                   6.1.7600.16385               DLL    
    ucmhc.dll                  6.1.7600.16385                 UCM
    udhisapi.dll               6.1.7600.16385              UPnP Device Host ISAPI Extension
    uexfat.dll                 6.1.7600.16385              eXfat Utility DLL
    ufat.dll                   6.1.7600.16385              FAT Utility DLL
    uianimation.dll            6.1.7600.16385              Windows Animation Manager
    uiautomationcore.dll       7.0.0.0                        Microsoft UI
    uicom.dll                  6.1.7600.16385              Add/Remove Modems
    uiribbon.dll               6.1.7600.16385                Windows
    uiribbonres.dll            6.1.7600.16385              Windows Ribbon Framework Resources
    ulib.dll                   6.1.7600.16385              DLL   
    umdmxfrm.dll               6.1.7600.16385              Unimodem Tranform Module
    unimdmat.dll               6.1.7600.16385              - AT   Unimodem
    uniplat.dll                6.1.7600.16385              Unimodem AT Mini Driver Platform Driver for Windows NT
    unrar.dll                  4.0.100.60                  
    untfs.dll                  6.1.7600.16385              NTFS Utility DLL
    upnp.dll                   6.1.7600.16385              API   UPnP
    upnphost.dll               6.1.7600.16385                PNP-
    ureg.dll                   6.1.7600.16385              Registry Utility DLL
    url.dll                    8.0.7600.16839              Internet Shortcut Shell Extension DLL
    urlmon.dll                 8.0.7600.16839               OLE32  Win32
    usbceip.dll                6.1.7600.16385               USBCEIP
    usbperf.dll                6.1.7600.16385               DLL   USB
    usbui.dll                  6.1.7600.16385              USB UI Dll
    user32.dll                 6.1.7600.16385                 USER API Windows
    useraccountcontrolsettings.dll  6.1.7600.16385                  
    usercpl.dll                6.1.7600.16385                
    userenv.dll                6.1.7600.16385              Userenv
    usp10.dll                  1.626.7600.16385            Uniscribe Unicode script processor
    utildll.dll                6.1.7600.16385                WinStation
    uudf.dll                   6.1.7600.16385              UDF Utility DLL
    uxinit.dll                 6.1.7600.16385              Windows User Experience Session Initialization Dll
    uxlib.dll                  6.1.7600.16385              Setup Wizard Framework
    uxlibres.dll               6.1.7600.16385              UXLib Resources
    uxtheme.dll                6.1.7600.16385                UxTheme (Microsoft)
    van.dll                    6.1.7600.16385                
    vault.dll                  6.1.7600.16385                -  Windows
    vaultcli.dll               6.1.7600.16385              Credential Vault Client Library
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbscript.dll               5.8.7600.16762              Microsoft  VBScript
    vcomp100.dll               10.0.30319.415              Microsoft C/C++ OpenMP Runtime
    vdmdbg.dll                 6.1.7600.16385              VDMDBG.DLL
    vds_ps.dll                 6.1.7600.16385              Microsoft Virtual Disk Service proxy/stub
    vdsbas.dll                 6.1.7600.16385                  
    vdsdyn.dll                 6.1.7600.16385                  VDS,  2.1.0.1
    vdsvd.dll                  6.1.7600.16385              VDS Virtual Disk Provider, Version 1.0
    verifier.dll               6.1.7600.16385              Standard application verifier provider dll
    version.dll                6.1.7600.16385              Version Checking and File Installation Libraries
    vfpodbc.dll                1.0.2.0                     vfpodbc
    vfwwdm32.dll               6.1.7600.16385               VfW MM Driver    WDM-
    vidreszr.dll               6.1.7600.16385              Windows Media Resizer
    virtdisk.dll               6.1.7600.16385              Virtual Disk API DLL
    vksaver.dll                2.2.2.0                     Music and video downloader for vkontakte.ru
    vpnikeapi.dll              6.1.7600.16385              VPN IKE API's
    vss_ps.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               6.1.7600.16385                    Microsoft
    w32topl.dll                6.1.7600.16385              Windows NT Topology Maintenance Tool
    wab32.dll                  6.1.7600.16385              Microsoft (R) Contacts DLL
    wab32res.dll               6.1.7600.16385               Microsoft (R) DLL
    wabsyncprovider.dll        6.1.7600.16385                 Microsoft Windows
    wavemsp.dll                6.1.7600.16385              Microsoft Wave MSP
    wbemcomn.dll               6.1.7600.16385              WMI
    wcnapi.dll                 6.1.7600.16385              Windows Connect Now - API Helper DLL
    wcncsvc.dll                6.1.7600.16385                Windows -   
    wcneapauthproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP Authenticator Proxy
    wcneappeerproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP PEER Proxy
    wcnwiz.dll                 6.1.7600.16385                Windows Connect Now
    wcspluginservice.dll       6.1.7600.16385               DLL WcsPlugInService
    wdc.dll                    6.1.7600.16385               
    wdi.dll                    6.1.7600.16385                Windows
    wdigest.dll                6.1.7600.16385              Microsoft Digest Access
    wdscore.dll                6.1.7600.16385              Panther Engine Module
    webcheck.dll               8.0.7600.16385               -
    webclnt.dll                6.1.7600.16385               DLL - DAV
    webio.dll                  6.1.7600.16688              API    
    webservices.dll            6.1.7600.16385                - Windows
    wecapi.dll                 6.1.7600.16385              Event Collector Configuration API
    wer.dll                    6.1.7600.16385                  Windows
    werdiagcontroller.dll      6.1.7600.16385              WER Diagnostic Controller
    werui.dll                  6.1.7600.16385               DLL      Windows
    wevtapi.dll                6.1.7600.16385              API    
    wevtfwd.dll                6.1.7600.16385              WS-Management Event Forwarding Plug-in
    wfapigp.dll                6.1.7600.16385              Windows Firewall GPO Helper dll
    wfhc.dll                   6.1.7600.16385               Windows.   
    whealogr.dll               6.1.7600.16385                WHEA
    whhelper.dll               6.1.7600.16385              DLL     winHttp
    wiaaut.dll                 6.1.7600.16385               WIA-
    wiadefui.dll               6.1.7600.16385                  WIA
    wiadss.dll                 6.1.7600.16385               WIA -  TWAIN
    wiaextensionhost64.dll     6.1.7600.16385              WIA Extension Host for thunking APIs from 32-bit to 64-bit process
    wiascanprofiles.dll        6.1.7600.16385              Microsoft Windows ScanProfiles
    wiashext.dll               6.1.7600.16385                     
    wiatrace.dll               6.1.7600.16385              WIA Tracing
    wiavideo.dll               6.1.7600.16385              WIA Video
    wimgapi.dll                6.1.7600.16385               Windows Imaging
    win32spl.dll               6.1.7600.16385                    
    winbio.dll                 6.1.7600.16385              API   Windows
    winbrand.dll               6.1.7600.16385              Windows Branding Resources
    wincredprovider.dll        6.1.7600.16385               DLL wincredprovider
    windowscodecs.dll          6.1.7600.16385              Microsoft Windows Codecs Library
    windowscodecsext.dll       6.1.7600.16385              Microsoft Windows Codecs Extended Library
    winfax.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    winhttp.dll                6.1.7600.16385               HTTP Windows
    wininet.dll                8.0.7600.16839                 Win32
    winipsec.dll               6.1.7600.16385              Windows IPsec SPD Client DLL
    winmm.dll                  6.1.7600.16385              MCI API DLL
    winnsi.dll                 6.1.7600.16385              Network Store Information RPC interface
    winrnr.dll                 6.1.7600.16385              LDAP RnR Provider DLL
    winrscmd.dll               6.1.7600.16385              remtsvc
    winrsmgr.dll               6.1.7600.16385              WSMan Shell API
    winrssrv.dll               6.1.7600.16385              winrssrv
    winsatapi.dll              6.1.7600.16385              Windows System Assessment Tool API
    winscard.dll               6.1.7600.16385              API - (Microsoft)
    winshfhc.dll               6.1.7600.16385              File Risk Estimation
    winsockhc.dll              6.1.7600.16385                   Winsock
    winsrpc.dll                6.1.7600.16385              WINS RPC LIBRARY
    winsta.dll                 6.1.7600.16385              Winstation Library
    winsync.dll                2007.94.7600.16385          Synchronization Framework
    winsyncmetastore.dll       2007.94.7600.16385          Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.7600.16385          Windows Synchronization Provider Framework
    wintrust.dll               6.1.7600.16493              Microsoft Trust Verification APIs
    winusb.dll                 6.1.7600.16385              Windows USB Driver User Library
    wkscli.dll                 6.1.7600.16385              Workstation Service Client DLL
    wksprtps.dll               6.1.7600.16385              WorkspaceRuntime ProxyStub DLL
    wlanapi.dll                6.1.7600.16385              Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                6.1.7600.16385               DLL    Netsh  WLAN
    wlanconn.dll               6.1.7600.16385                Dot11
    wlandlg.dll                6.1.7600.16385                   
    wlangpui.dll               6.1.7600.16385               "   "
    wlanhlp.dll                6.1.7600.16385              Windows Wireless LAN 802.11 Client Side Helper API
    wlaninst.dll               6.1.7600.16385              Windows NET Device Class Co-Installer for Wireless LAN
    wlanmm.dll                 6.1.7600.16385                Dot11   
    wlanmsm.dll                6.1.7600.16385              Windows Wireless LAN 802.11 MSM DLL
    wlanpref.dll               6.1.7600.16385                
    wlansec.dll                6.1.7600.16385              Windows Wireless LAN 802.11 MSM Security Module DLL
    wlanui.dll                 6.1.7600.16385                 
    wlanutil.dll               6.1.7600.16385               DLL     Windows   802.11
    wldap32.dll                6.1.7600.16385              Win32 LDAP API DLL
    wlgpclnt.dll               6.1.7600.16385                 802.11
    wls0wndh.dll               6.1.7600.16385              Session0 Viewer Window Hook DLL
    wmadmod.dll                6.1.7600.16385              Windows Media Audio Decoder
    wmadmoe.dll                6.1.7600.16385              Windows Media Audio 10 Encoder/Transcoder
    wmasf.dll                  12.0.7600.16385             Windows Media ASF DLL
    wmcodecdspps.dll           6.1.7600.16385              Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.7600.16385             Windows Media Device Manager Logger
    wmdmps.dll                 12.0.7600.16385             Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               12.0.7600.16385             Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               12.0.7600.16385             Windows Media DRM for Network Devices DLL
    wmdrmsdk.dll               11.0.7600.16385             Windows Media DRM SDK DLL
    wmerror.dll                12.0.7600.16385               Windows Media ()
    wmi.dll                    6.1.7600.16385              WMI DC and DP functionality
    wmidx.dll                  12.0.7600.16385             Windows Media Indexer DLL
    wmiprop.dll                6.1.7600.16385                  WDM
    wmnetmgr.dll               12.0.7600.16385             Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.7600.16667             Windows Media Player
    wmpcm.dll                  12.0.7600.16385             Windows Media Player Compositing Mixer
    wmpdui.dll                 12.0.7600.16385             Windows Media Player UI Engine
    wmpdxm.dll                 12.0.7600.16385             Windows Media Player Extension
    wmpeffects.dll             12.0.7600.16385             Windows Media Player Effects
    wmpencen.dll               12.0.7600.16385             Windows Media Player Encoding Module
    wmphoto.dll                6.1.7600.16385               Windows Media
    wmploc.dll                 12.0.7600.16667               Windows Media
    wmpmde.dll                 12.0.7600.16661             WMPMDE DLL
    wmpps.dll                  12.0.7600.16385             Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.7600.16385                Windows Media
    wmpsrcwp.dll               12.0.7600.16385             WMPSrcWp Module
    wmsgapi.dll                6.1.7600.16385              WinLogon IPC Client
    wmspdmod.dll               6.1.7600.16385              Windows Media Audio Voice Decoder
    wmspdmoe.dll               6.1.7600.16385              Windows Media Audio Voice Encoder
    wmv9vcm.dll                9.0.1.369                   Windows Media Video 9 VCM
    wmvcore.dll                12.0.7600.16385             Windows Media Playback/Authoring DLL
    wmvdecod.dll               6.1.7600.16385              Windows Media Video Decoder
    wmvdspa.dll                6.1.7600.16385              Windows Media Video DSP Components - Advanced
    wmvencod.dll               6.1.7600.16385              Windows Media Video 9 Encoder
    wmvsdecd.dll               6.1.7600.16385              Windows Media Screen Decoder
    wmvsencd.dll               6.1.7600.16385              Windows Media Screen Encoder
    wmvxencd.dll               6.1.7600.16385              Windows Media Video Encoder
    wow32.dll                  6.1.7600.16850              Wow32
    wpc.dll                    1.0.0.1                        
    wpcao.dll                  6.1.7600.16385                WPC
    wpcsvc.dll                 1.0.0.1                         Windows
    wpdshext.dll               6.1.7600.16385                  
    wpdshserviceobj.dll        6.1.7600.16385              Windows Portable Device Shell Service Object
    wpdsp.dll                  6.1.7600.16385              WMDM Service Provider for Windows Portable Devices
    wpdwcn.dll                 6.1.7600.16385                    WCN
    wrap_oal.dll               2.2.0.5                     OpenAL32
    ws2_32.dll                 6.1.7600.16385              32-  Windows Socket 2.0
    ws2help.dll                6.1.7600.16385              Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 6.1.7600.16385              Windows Security Center API
    wscinterop.dll             6.1.7600.16385              Windows Health Center WSC Interop
    wscisvif.dll               6.1.7600.16385              Windows Security Center ISV API
    wscmisetup.dll             6.1.7600.16385              Installers for Winsock Transport and Name Space Providers
    wscproxystub.dll           6.1.7600.16385              Windows Security Center ISV Proxy Stub
    wsdapi.dll                 6.1.7600.16385              -   DLL API- 
    wsdchngr.dll               6.1.7600.16385              WSD Challenge Component
    wsecedit.dll               6.1.7600.16385                 
    wshbth.dll                 6.1.7600.16385              Windows Sockets Helper DLL
    wshcon.dll                 5.8.7600.16385              Microsoft  Windows Script Controller
    wshelper.dll               6.1.7600.16385               DLL    Winsock Net
    wshext.dll                 5.8.7600.16385              Microsoft  Shell Extension for Windows Script Host
    wship6.dll                 6.1.7600.16385               DLL  Winsock2 (TL/IPv6)
    wshirda.dll                6.1.7600.16385              Windows Sockets Helper DLL
    wshqos.dll                 6.1.7600.16385               DLL   QoS Winsock2
    wshrm.dll                  6.1.7600.16385                DLL   Windows  PGM
    wshtcpip.dll               6.1.7600.16385               DLL   Winsock2 (TL/IPv4)
    wsmanmigrationplugin.dll   6.1.7600.16385              WinRM Migration Plugin
    wsmauto.dll                6.1.7600.16385              WSMAN Automation
    wsmplpxy.dll               6.1.7600.16385              wsmplpxy
    wsmres.dll                 6.1.7600.16385               DLL  WSMan
    wsmsvc.dll                 6.1.7600.16385               WSMan
    wsmwmipl.dll               6.1.7600.16385              WSMAN WMI Provider
    wsnmp32.dll                6.1.7600.16385              Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                6.1.7600.16385              Windows Socket 32-Bit DLL
    wtsapi32.dll               6.1.7600.16385              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  7.3.7600.16385              API    Windows
    wudriver.dll               7.3.7600.16385              Windows Update WUDriver Stub
    wups.dll                   7.3.7600.16385              Windows Update client proxy stub
    wuwebv.dll                 7.3.7600.16385              Windows Update Vista Web Control
    wvc.dll                    6.1.7600.16385              Windows Visual Components
    wwanapi.dll                6.1.7600.16385              Mbnapi
    wwapi.dll                  8.1.2.0                     WWAN API
    wzcdlg.dll                 6.1.7600.16385              Windows Connect Now - Flash Config Enrollee
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput9_1_0.dll            6.1.7600.16385                XNA
    xlive.dll                  3.5.88.0                    Games for Windows - LIVE DLL
    xlivefnt.dll               3.5.88.0                    XLive Fonts DLL
    xliveinstall.dll           3.2.6.0                     XLiveInstall DLL
    xmlfilter.dll              2008.0.7600.16385            XML
    xmllite.dll                1.3.1000.0                  Microsoft XmlLite Library
    xmlprovi.dll               6.1.7600.16385              Network Provisioning Service Client API
    xolehlp.dll                2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsfilt.dll                6.1.7600.16385              XML Paper Specification Document IFilter
    xpsgdiconverter.dll        6.1.7600.16385              XPS to GDI Converter
    xpsprint.dll               6.1.7600.16385              XPS Printing DLL
    xpsrasterservice.dll       6.1.7600.16385              XPS Rasterization Service Component
    xpsservices.dll            6.1.7600.16385              Xps Object Model in memory creation and deserialization
    xpsshhdr.dll               6.1.7600.16385              Package Document Shell Extension Handler
    xpssvcs.dll                6.1.7600.16385              Native Code Xps Services Library
    xvidcore.dll                                           
    xvidvfw.dll                                            
    xwizards.dll               6.1.7600.16385                 
    xwreg.dll                  6.1.7600.16385              Extensible Wizard Registration Manager Module
    xwtpdui.dll                6.1.7600.16385                   DUI
    xwtpw32.dll                6.1.7600.16385                   Win32
    yv12vfw.dll                1.3.0.0                     Helix YV12 YUV Codec
    zipfldr.dll                6.1.7600.16385               ZIP-


--------[   ]------------------------------------------------------------------------------------------------

     :
                         02.11.2011 15:45:27
                           02.11.2011 21:39:28
                                            02.11.2011 23:03:08
                                             5036  (0 ., 1 , 23 , 56 )

      :
                                     08.08.2011 21:41:01
                            08.08.2011 21:40:01
                                        2816148  (32 ., 14 , 15 , 48 )
                                       5410304  (62 ., 14 , 51 , 44 )
                                  48291  (0 ., 13 , 24 , 51 )
                                 1090955  (12 ., 15 , 2 , 35 )
                                       326
                                34.23%

      (" "):
                                              0

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    Users                                                                              C:\Users
    ADMIN$                                    Admin                           C:\Windows
    C$                                                           C:\
    D$                                                           D:\
    IPC$                            IPC            IPC                             


--------[  ]------------------------------------------------------------------------------------------------

       :
                                          
                                             Aparratus-
                              
                      
      ./.                      0 / 42 .
                                  0 
                                     
                                       
                                30 
                                30 


--------[    ]----------------------------------------------------------------------------------------------

    Aparratus                                     APARRATUS-              Aparratus-
    Aparratus                                     APARRATUS-              Aparratus-
    UpdatusUser         UpdatusUser               APARRATUS-              Aparratus-


--------[  ]------------------------------------------------------------------------------------------------

  [ Aparratus ]

     :
                                         Aparratus
                                               Aparratus
                                               HomeUsers; 
                                     2230
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [ HomeGroupUser$ ]

     :
                                         HomeGroupUser$
                                               HomeGroupUser$
                                                       
                                               HomeUsers
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [ UpdatusUser ]

     :
                                         UpdatusUser
                                               UpdatusUser
                                                  NVIDIA
                                     59
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                 /
                                               HomeUsers; 
                                     1
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[   ]--------------------------------------------------------------------------------------------

  [ HomeUsers ]

      :
                                             HomeUsers Security Group

     :
      Aparratus                                         
      HomeGroupUser$                                    HomeGroupUser$
                                           

  [ IIS_IUSRS ]

      :
                                              ,    IIS.

     :
      IUSR                                              

  [  ]

      :
                                               ,         

     :
      Aparratus                                         
                                           

  [  ]

      :
                                                   ,   ,     "",     .

     :
                                                   

  [   ]

      :
                                                 .

  [   ]

      :
                                                         .

  [    ]

      :
                                                         

  [   ]

      :
                                                        

  [  DCOM ]

      :
                                                 ,     DCOM   .

  [    ]

      :
                                                     ,         ,        .

  [    ]

      :
                                                  ,       

  [     ]

      :
                                                     

  [  ]

      :
                                                         

     :
                                           
                                       

  [  ]

      :
                                                 

  [    ]

      :
                                                      


--------[   ]-------------------------------------------------------------------------------------------

  [ None ]

      :
                                             Ordinary users

     :
      Aparratus                                         
      HomeGroupUser$                                    HomeGroupUser$
      UpdatusUser                                       UpdatusUser
                                           
                                                   


--------[  Windows ]-----------------------------------------------------------------------------------------------

  [ NVIDIA GeForce GTX 580 ]

     :
                                      NVIDIA GeForce GTX 580
                                          GeForce GTX 580
       BIOS                                       Version 70.10.20.0.1
                                      GeForce GTX 580
       DAC                                           Integrated RAMDAC
                                            15.10.2011
                                          8.17.12.8562 - nVIDIA ForceWare 285.62
                                       NVIDIA
                                           1536 

     :
      nvd3dumx                                          8.17.12.8562
      nvwgf2umx                                         8.17.12.8562
      nvwgf2umx                                         8.17.12.8562
      nvd3dum                                           8.17.12.8562 - nVIDIA ForceWare 285.62
      nvwgf2um                                          8.17.12.8562
      nvwgf2um                                          8.17.12.8562

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ NVIDIA GeForce GTX 580 ]

     :
                                      NVIDIA GeForce GTX 580
                                          GeForce GTX 580
       BIOS                                       Version 70.10.20.0.1
                                      GeForce GTX 580
       DAC                                           Integrated RAMDAC
                                            15.10.2011
                                          8.17.12.8562 - nVIDIA ForceWare 285.62
                                       NVIDIA
                                           1536 

     :
      nvd3dumx                                          8.17.12.8562
      nvwgf2umx                                         8.17.12.8562
      nvwgf2umx                                         8.17.12.8562
      nvd3dum                                           8.17.12.8562 - nVIDIA ForceWare 285.62
      nvwgf2um                                          8.17.12.8562
      nvwgf2um                                          8.17.12.8562

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[  PCI / AGP ]---------------------------------------------------------------------------------------------

    nVIDIA GeForce GTX 580                                                            
    nVIDIA GeForce GTX 580                                                            3D-


--------[   ]---------------------------------------------------------------------------------------

  [ PCI Express 2.0 x16: Zotac GeForce GTX 580 ]

      :
                                            Zotac GeForce GTX 580
       BIOS                                       70.10.20.00.01
                                       GF110
      PCI-                                    10DE-1080 / 19DA-1203  (Rev A1)
                                       3000 .
                                  40 nm
                                         520 mm2
                                                 PCI Express 2.0 x16 @ x16
                                           1536 
        (Geometric Domain)                     405   (: 772 MHz)
        (Shader Domain)                        810   (: 1544 MHz)
       RAMDAC                                    400 
                                     48
                                 64
                                     512  (v5.0)
        DirectX                      DirectX v11
                            19440 /
                            25920 /

      :
                                                 GDDR5
                                              384 
                                         162  (QDR)  (: 1002 MHz)
                                      648 
                                   30.4 /

    :
                                    29%
                                        9%
      Video Engine                                      21%

    nVIDIA ForceWare Clocks:
      Standard 2D                                        : 50 , : 101 , : 135 
      Low-Power 3D                                       : 405 , : 810 , : 324 
      Performance 3D                                     : 772 , : 1544 , : 2004 

      :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

    nVIDIA GPU Registers:
      nv-000000                                         0C8000A1
      nv-0010F0                                         00000000
      nv-001218                                         00000000
      nv-001540                                         00000000
      nv-0015F4                                         00000000
      nv-0015F8                                         00000000
      nv-0015FC                                         00000000
      nv-001600                                         00000000
      nv-001850                                         00000000
      nv-004000                                         00000000
      nv-004004                                         00000000
      nv-004008                                         00000000
      nv-00400C                                         00000000
      nv-004018                                         00000000
      nv-00401C                                         00000000
      nv-004020                                         00000000
      nv-004024                                         00000000
      nv-004028                                         00000000
      nv-00402C                                         00000000
      nv-004120                                         00000000
      nv-004124                                         00000000
      nv-004128                                         00000000
      nv-004200                                         00000000
      nv-004220                                         00000000
      nv-00C040                                         00000000
      nv-00E114                                         0000021C
      nv-00E118                                         000000E0
      nv-00E11C                                         00000001
      nv-00E120                                         00000000
      nv-00E728                                         002E002F
      nv-00E820                                         01030005
      nv-00E8A0                                         00000000
      nv-020008                                         C00836D2
      nv-020014                                         FA2903A0
      nv-020400                                         0000002F
      nv-022438                                         00000006
      nv-02243C                                         00000000
      nv-022554                                         00000000
      nv-100000                                         00000000
      nv-100200                                         00000000
      nv-10020C                                         00000000
      nv-100214                                         00000000
      nv-100474                                         00000000
      nv-100714                                         00000303
      nv-100914                                         00000000
      nv-101000                                         A040408A
      nv-10F290                                         040E120A
      nv-10F294                                         3830C287
      nv-10F590                                         00100204
      nv-121C74                                         00000006
      nv-300000                                         EB72AA55
      nv-310000                                         9BAE8AE9
      nv-419E9C                                         00000030
      nv-700000                                         CEFEEFEF
      nv-7E0000                                         EB72AA55

  [ nVIDIA SLI ]

    nVIDIA SLI:
       SLI                                        


--------[  ]-----------------------------------------------------------------------------------------------------

  [ ViewSonic VX2240w ]

     :
                                             ViewSonic VX2240w
      ID                                        VSC6B20
                                                  VX2240w
                                             22" LCD (WSXGA+)
                                              42 / 2007
                                           QRB074220815
      .                         49 cm x 29 cm (22.4")
                                       5:3
                                                 300 cd/m2
                                           1000:1
                                              170/160
                                                   DSub, DVI-D
                                            24 - 82 
                                           50 - 75 
                           170 
                                  1680 x 1050
                                                   2.20
        DPMS                        Active-Off

     :
      640 x 480                                         75 
      800 x 480                                         75 
      800 x 600                                         75 
      1024 x 600                                        75 
      1024 x 768                                        75 
      1152 x 864                                        75 
      1280 x 720                                        75 
      1280 x 768                                        75 
      1280 x 800                                        75 
      1280 x 1024                                       75 
      1366 x 768                                        75 
      1400 x 1050                                       70 
      1440 x 900                                        75 
      1680 x 1050                                       70 

     :
                                                   ViewSonic Corporation
                                     http://www.viewsonic.com/products
                                       http://www.viewsonic.com/support/downloads/drivers
                                     http://www.aida64.com/driver-updates


--------[   ]------------------------------------------------------------------------------------------------

      :
                                     
                                              1680 x 1050
                                            32 
                                       1
                                        96 dpi
        /                         36 / 36
                                     51
                                      59 

      :
       -                             
                                              
                                      
                              
      ClearType                                         
             
                                
                                  
                                      
                                  
                                 
                                            
                                   
       /           
                                           
                              
                               
                            
                              
      Windows Aero                                      
       Windows Plus!                               


--------[  ]-----------------------------------------------------------------------------------------------

    \\.\DISPLAY1           (0,0)          (1680,1050)


--------[  ]-------------------------------------------------------------------------------------------------

    640 x 480           8   59 Hz
    640 x 480           8   60 Hz
    640 x 480           8   72 Hz
    640 x 480           8   75 Hz
    640 x 480          16   59 Hz
    640 x 480          16   60 Hz
    640 x 480          16   72 Hz
    640 x 480          16   75 Hz
    640 x 480          32   59 Hz
    640 x 480          32   60 Hz
    640 x 480          32   72 Hz
    640 x 480          32   75 Hz
    720 x 480           8   56 Hz
    720 x 480           8   56 Hz
    720 x 480           8   56 Hz
    720 x 480           8   60 Hz
    720 x 480           8   60 Hz
    720 x 480           8   60 Hz
    720 x 480           8   72 Hz
    720 x 480           8   72 Hz
    720 x 480           8   72 Hz
    720 x 480           8   75 Hz
    720 x 480           8   75 Hz
    720 x 480           8   75 Hz
    720 x 480          16   56 Hz
    720 x 480          16   56 Hz
    720 x 480          16   56 Hz
    720 x 480          16   60 Hz
    720 x 480          16   60 Hz
    720 x 480          16   60 Hz
    720 x 480          16   72 Hz
    720 x 480          16   72 Hz
    720 x 480          16   72 Hz
    720 x 480          16   75 Hz
    720 x 480          16   75 Hz
    720 x 480          16   75 Hz
    720 x 480          32   56 Hz
    720 x 480          32   56 Hz
    720 x 480          32   56 Hz
    720 x 480          32   60 Hz
    720 x 480          32   60 Hz
    720 x 480          32   60 Hz
    720 x 480          32   72 Hz
    720 x 480          32   72 Hz
    720 x 480          32   72 Hz
    720 x 480          32   75 Hz
    720 x 480          32   75 Hz
    720 x 480          32   75 Hz
    720 x 576           8   56 Hz
    720 x 576           8   56 Hz
    720 x 576           8   56 Hz
    720 x 576           8   60 Hz
    720 x 576           8   60 Hz
    720 x 576           8   60 Hz
    720 x 576           8   72 Hz
    720 x 576           8   72 Hz
    720 x 576           8   72 Hz
    720 x 576           8   75 Hz
    720 x 576           8   75 Hz
    720 x 576           8   75 Hz
    720 x 576          16   56 Hz
    720 x 576          16   56 Hz
    720 x 576          16   56 Hz
    720 x 576          16   60 Hz
    720 x 576          16   60 Hz
    720 x 576          16   60 Hz
    720 x 576          16   72 Hz
    720 x 576          16   72 Hz
    720 x 576          16   72 Hz
    720 x 576          16   75 Hz
    720 x 576          16   75 Hz
    720 x 576          16   75 Hz
    720 x 576          32   56 Hz
    720 x 576          32   56 Hz
    720 x 576          32   56 Hz
    720 x 576          32   60 Hz
    720 x 576          32   60 Hz
    720 x 576          32   60 Hz
    720 x 576          32   72 Hz
    720 x 576          32   72 Hz
    720 x 576          32   72 Hz
    720 x 576          32   75 Hz
    720 x 576          32   75 Hz
    720 x 576          32   75 Hz
    800 x 600           8   56 Hz
    800 x 600           8   60 Hz
    800 x 600           8   72 Hz
    800 x 600           8   75 Hz
    800 x 600          16   56 Hz
    800 x 600          16   60 Hz
    800 x 600          16   72 Hz
    800 x 600          16   75 Hz
    800 x 600          32   56 Hz
    800 x 600          32   60 Hz
    800 x 600          32   72 Hz
    800 x 600          32   75 Hz
    1024 x 768          8   60 Hz
    1024 x 768          8   70 Hz
    1024 x 768          8   75 Hz
    1024 x 768         16   60 Hz
    1024 x 768         16   70 Hz
    1024 x 768         16   75 Hz
    1024 x 768         32   60 Hz
    1024 x 768         32   70 Hz
    1024 x 768         32   75 Hz
    1152 x 864          8   75 Hz
    1152 x 864         16   75 Hz
    1152 x 864         32   75 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    1280 x 800          8   60 Hz
    1280 x 800          8   60 Hz
    1280 x 800          8   60 Hz
    1280 x 800         16   60 Hz
    1280 x 800         16   60 Hz
    1280 x 800         16   60 Hz
    1280 x 800         32   60 Hz
    1280 x 800         32   60 Hz
    1280 x 800         32   60 Hz
    1280 x 960          8   60 Hz
    1280 x 960         16   60 Hz
    1280 x 960         32   60 Hz
    1280 x 1024         8   60 Hz
    1280 x 1024         8   75 Hz
    1280 x 1024        16   60 Hz
    1280 x 1024        16   75 Hz
    1280 x 1024        32   60 Hz
    1280 x 1024        32   75 Hz
    1360 x 768          8   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         32   60 Hz
    1360 x 768         32   60 Hz
    1360 x 768         32   60 Hz
    1366 x 768          8   60 Hz
    1366 x 768          8   60 Hz
    1366 x 768          8   60 Hz
    1366 x 768         16   60 Hz
    1366 x 768         16   60 Hz
    1366 x 768         16   60 Hz
    1366 x 768         32   60 Hz
    1366 x 768         32   60 Hz
    1366 x 768         32   60 Hz
    1400 x 1050         8   60 Hz
    1400 x 1050        16   60 Hz
    1400 x 1050        32   60 Hz
    1440 x 900          8   60 Hz
    1440 x 900         16   60 Hz
    1440 x 900         32   60 Hz
    1600 x 900          8   59 Hz
    1600 x 900          8   59 Hz
    1600 x 900          8   59 Hz
    1600 x 900          8   60 Hz
    1600 x 900          8   60 Hz
    1600 x 900          8   60 Hz
    1600 x 900         16   59 Hz
    1600 x 900         16   59 Hz
    1600 x 900         16   59 Hz
    1600 x 900         16   60 Hz
    1600 x 900         16   60 Hz
    1600 x 900         16   60 Hz
    1600 x 900         32   59 Hz
    1600 x 900         32   59 Hz
    1600 x 900         32   59 Hz
    1600 x 900         32   60 Hz
    1600 x 900         32   60 Hz
    1600 x 900         32   60 Hz
    1600 x 1024         8   59 Hz
    1600 x 1024         8   59 Hz
    1600 x 1024         8   59 Hz
    1600 x 1024         8   60 Hz
    1600 x 1024         8   60 Hz
    1600 x 1024         8   60 Hz
    1600 x 1024        16   59 Hz
    1600 x 1024        16   59 Hz
    1600 x 1024        16   59 Hz
    1600 x 1024        16   60 Hz
    1600 x 1024        16   60 Hz
    1600 x 1024        16   60 Hz
    1600 x 1024        32   59 Hz
    1600 x 1024        32   59 Hz
    1600 x 1024        32   59 Hz
    1600 x 1024        32   60 Hz
    1600 x 1024        32   60 Hz
    1600 x 1024        32   60 Hz
    1600 x 1200         8   60 Hz
    1600 x 1200        16   60 Hz
    1600 x 1200        32   60 Hz
    1680 x 1050         8   59 Hz
    1680 x 1050         8   60 Hz
    1680 x 1050        16   59 Hz
    1680 x 1050        16   60 Hz
    1680 x 1050        32   59 Hz
    1680 x 1050        32   60 Hz


--------[ OpenGL ]------------------------------------------------------------------------------------------------------

     OpenGL:
                                           NVIDIA Corporation
      Renderer                                          GeForce GTX 580/PCI/SSE2
                                                  4.2.0
                                    4.20 NVIDIA via Cg compiler
      OpenGL DLL                                        6.1.7600.16385(win7_rtm.090713-1255)
      Multitexture Texture Units                        4
      Occlusion Query Counter Bits                      32
      Sub-Pixel Precision                               8 
      Max Viewport Size                                 16384 x 16384
      Max Cube Map Texture Size                         16384 x 16384
      Max Rectangle Texture Size                        16384 x 16384
      Max 3D Texture Size                               2048 x 2048 x 2048
      Max Anisotropy                                    16
      Max Clipping Planes                               8
      Max Display-List Nesting Level                    64
      Max Draw Buffers                                  8
      Max Evaluator Order                               8
      Max General Register Combiners                    8
      Max Light Sources                                 8
      Max Pixel Map Table Size                          65536
      Min / Max Program Texel Offset                    -8 / 7
      Max Texture Array Layers                          2048
      Max Texture LOD Bias                              15
      Max Vertex Array Range Element Size               1048575

     OpenGL:
      OpenGL 1.1                                          (100%)
      OpenGL 1.2                                          (100%)
      OpenGL 1.3                                          (100%)
      OpenGL 1.4                                          (100%)
      OpenGL 1.5                                          (100%)
      OpenGL 2.0                                          (100%)
      OpenGL 2.1                                          (100%)
      OpenGL 3.0                                          (100%)
      OpenGL 3.1                                          (100%)
      OpenGL 3.2                                          (100%)
      OpenGL 3.3                                          (100%)
      OpenGL 4.0                                          (100%)
      OpenGL 4.1                                          (100%)
      OpenGL 4.2                                          (100%)

    Max Stack Depth:
      Attribute Stack                                   16
      Client Attribute Stack                            16
      Modelview Matrix Stack                            32
      Name Stack                                        128
      Projection Matrix Stack                           4
      Texture Matrix Stack                              10

    Draw Range Elements:
      Max Index Count                                   1048576
      Max Vertex Count                                  1048576

    Extended Lighting Parameters:
      Max Shininess                                     128
      Max Spot Exponent                                 128

    Transform Feedback:
      Max Interleaved Components                        128
      Max Separate Attributes                           4
      Max Separate Components                           4

    Framebuffer Object:
      Max Color Attachments                             8
      Max Render Buffer Size                            16384 x 16384

    Imaging:
      Max Color Matrix Stack Depth                      2
      Max Convolution Width / Height                    11 / 11

    Vertex Shader:
      Max Uniform Vertex Components                     4096
      Max Varying Floats                                124
      Max Vertex Texture Image Units                    32
      Max Combined Texture Image Units                  160

    Geometry Shader:
      Max Geometry Texture Units                        32
      Max Varying Components                            124
      Max Geometry Varying Components                   124
      Max Vertex Varying Components                     124
      Max Geometry Uniform Components                   2048
      Max Geometry Output Vertices                      1024
      Max Geometry Total Output Components              1024

    Fragment Shader:
      Max Uniform Fragment Components                   2048

    Vertex Program:
      Max Local Parameters                              1024
      Max Environment Parameters                        256
      Max Program Matrices                              8
      Max Program Matrix Stack Depth                    1
      Max Tracking Matrices                             8
      Max Tracking Matrix Stack Depth                   1
      Max Vertex Attributes                             16
      Max Instructions                                  16384
      Max Native Instructions                           16384
      Max Temporaries                                   4096
      Max Native Temporaries                            4096
      Max Parameters                                    1024
      Max Native Parameters                             1024
      Max Attributes                                    16
      Max Native Attributes                             16
      Max Address Registers                             2
      Max Native Address Registers                      2

    Fragment Program:
      Max Local Parameters                              512
      Max Environment Parameters                        256
      Max Texture Coordinates                           8
      Max Texture Image Units                           32
      Max Instructions                                  16384
      Max Native Instructions                           16384
      Max Temporaries                                   4096
      Max Native Temporaries                            4096
      Max Parameters                                    1024
      Max Native Parameters                             1024
      Max Attributes                                    16
      Max Native Attributes                             16
      Max Address Registers                             1
      Max Native Address Registers                      1
      Max ALU Instructions                              16384
      Max Native ALU Instructions                       16384
      Max Texture Instructions                          16384
      Max Native Texture Instructions                   16384
      Max Texture Indirections                          16384
      Max Native Texture Indirections                   16384
      Max Execution Instructions                        16777216
      Max Call Stack Depth                              32
      Max If Statement Depth                            64
      Max Loop Depth                                    64
      Max Loop Count                                    16777216

     OpenGL:
      GL_3DFX_multisample                                
      GL_3DFX_tbuffer                                    
      GL_3DFX_texture_compression_FXT1                   
      GL_3DL_direct_texture_access2                      
      GL_3Dlabs_multisample_transparency_id              
      GL_3Dlabs_multisample_transparency_range           
      GL_AMD_blend_minmax_factor                         
      GL_AMD_conservative_depth                          
      GL_AMD_debug_output                                
      GL_AMD_depth_clamp_separate                        
      GL_AMD_draw_buffers_blend                          
      GL_AMD_name_gen_delete                             
      GL_AMD_performance_monitor                         
      GL_AMD_sample_positions                            
      GL_AMD_seamless_cubemap_per_texture                
      GL_AMD_shader_stencil_export                       
      GL_AMD_shader_trace                                
      GL_AMD_texture_compression_dxt6                    
      GL_AMD_texture_compression_dxt7                    
      GL_AMD_texture_cube_map_array                      
      GL_AMD_texture_texture4                            
      GL_AMD_transform_feedback3_lines_triangles         
      GL_AMD_vertex_shader_tessellator                   
      GL_AMDX_debug_output                               
      GL_AMDX_name_gen_delete                            
      GL_AMDX_random_access_target                       
      GL_AMDX_vertex_shader_tessellator                  
      GL_APPLE_aux_depth_stencil                         
      GL_APPLE_client_storage                            
      GL_APPLE_element_array                             
      GL_APPLE_fence                                     
      GL_APPLE_float_pixels                              
      GL_APPLE_flush_buffer_range                        
      GL_APPLE_flush_render                              
      GL_APPLE_object_purgeable                          
      GL_APPLE_packed_pixel                              
      GL_APPLE_packed_pixels                             
      GL_APPLE_pixel_buffer                              
      GL_APPLE_rgb_422                                   
      GL_APPLE_specular_vector                           
      GL_APPLE_texture_range                             
      GL_APPLE_transform_hint                            
      GL_APPLE_vertex_array_object                       
      GL_APPLE_vertex_array_range                        
      GL_APPLE_vertex_program_evaluators                 
      GL_APPLE_ycbcr_422                                 
      GL_ARB_base_instance                              
      GL_ARB_blend_func_extended                        
      GL_ARB_color_buffer_float                         
      GL_ARB_compatibility                              
      GL_ARB_compressed_texture_pixel_storage           
      GL_ARB_conservative_depth                         
      GL_ARB_copy_buffer                                
      GL_ARB_debug_output                                
      GL_ARB_depth_buffer_float                         
      GL_ARB_depth_clamp                                
      GL_ARB_depth_texture                              
      GL_ARB_draw_buffers                               
      GL_ARB_draw_buffers_blend                         
      GL_ARB_draw_elements_base_vertex                  
      GL_ARB_draw_indirect                              
      GL_ARB_draw_instanced                             
      GL_ARB_ES2_compatibility                          
      GL_ARB_explicit_attrib_location                   
      GL_ARB_fragment_coord_conventions                 
      GL_ARB_fragment_program                           
      GL_ARB_fragment_program_shadow                    
      GL_ARB_fragment_shader                            
      GL_ARB_framebuffer_object                         
      GL_ARB_framebuffer_sRGB                           
      GL_ARB_geometry_shader4                           
      GL_ARB_get_program_binary                         
      GL_ARB_gpu_shader_fp64                            
      GL_ARB_gpu_shader5                                
      GL_ARB_half_float_pixel                           
      GL_ARB_half_float_vertex                          
      GL_ARB_imaging                                    
      GL_ARB_instanced_arrays                           
      GL_ARB_internalformat_query                       
      GL_ARB_make_current_read                           
      GL_ARB_map_buffer_alignment                       
      GL_ARB_map_buffer_range                           
      GL_ARB_matrix_palette                              
      GL_ARB_multisample                                
      GL_ARB_multitexture                               
      GL_ARB_occlusion_query                            
      GL_ARB_occlusion_query2                           
      GL_ARB_pixel_buffer_object                        
      GL_ARB_point_parameters                           
      GL_ARB_point_sprite                               
      GL_ARB_provoking_vertex                           
      GL_ARB_robustness                                 
      GL_ARB_sample_shading                             
      GL_ARB_sampler_objects                            
      GL_ARB_seamless_cube_map                          
      GL_ARB_separate_shader_objects                    
      GL_ARB_shader_atomic_counters                     
      GL_ARB_shader_bit_encoding                        
      GL_ARB_shader_image_load_store                    
      GL_ARB_shader_objects                             
      GL_ARB_shader_precision                           
      GL_ARB_shader_stencil_export                       
      GL_ARB_shader_subroutine                          
      GL_ARB_shader_texture_lod                          
      GL_ARB_shading_language_100                       
      GL_ARB_shading_language_120                        
      GL_ARB_shading_language_420pack                   
      GL_ARB_shading_language_include                   
      GL_ARB_shading_language_packing                   
      GL_ARB_shadow                                     
      GL_ARB_shadow_ambient                              
      GL_ARB_swap_buffers                                
      GL_ARB_sync                                       
      GL_ARB_tessellation_shader                        
      GL_ARB_texture_border_clamp                       
      GL_ARB_texture_buffer_object                      
      GL_ARB_texture_buffer_object_rgb32                
      GL_ARB_texture_compression                        
      GL_ARB_texture_compression_bptc                   
      GL_ARB_texture_compression_rgtc                   
      GL_ARB_texture_cube_map                           
      GL_ARB_texture_cube_map_array                     
      GL_ARB_texture_env_add                            
      GL_ARB_texture_env_combine                        
      GL_ARB_texture_env_crossbar                       
      GL_ARB_texture_env_dot3                           
      GL_ARB_texture_float                              
      GL_ARB_texture_gather                             
      GL_ARB_texture_mirrored_repeat                    
      GL_ARB_texture_multisample                        
      GL_ARB_texture_non_power_of_two                   
      GL_ARB_texture_query_lod                          
      GL_ARB_texture_rectangle                          
      GL_ARB_texture_rg                                 
      GL_ARB_texture_rgb10_a2ui                         
      GL_ARB_texture_snorm                               
      GL_ARB_texture_storage                            
      GL_ARB_texture_swizzle                            
      GL_ARB_timer_query                                
      GL_ARB_transform_feedback_instanced               
      GL_ARB_transform_feedback2                        
      GL_ARB_transform_feedback3                        
      GL_ARB_transpose_matrix                           
      GL_ARB_uber_buffers                                
      GL_ARB_uber_mem_image                              
      GL_ARB_uber_vertex_array                           
      GL_ARB_uniform_buffer_object                      
      GL_ARB_vertex_array_bgra                          
      GL_ARB_vertex_array_object                        
      GL_ARB_vertex_attrib_64bit                        
      GL_ARB_vertex_blend                                
      GL_ARB_vertex_buffer_object                       
      GL_ARB_vertex_program                             
      GL_ARB_vertex_shader                              
      GL_ARB_vertex_type_2_10_10_10_rev                 
      GL_ARB_viewport_array                             
      GL_ARB_window_pos                                 
      GL_ATI_array_rev_comps_in_4_bytes                  
      GL_ATI_blend_equation_separate                     
      GL_ATI_blend_weighted_minmax                       
      GL_ATI_draw_buffers                               
      GL_ATI_element_array                               
      GL_ATI_envmap_bumpmap                              
      GL_ATI_fragment_shader                             
      GL_ATI_lock_texture                                
      GL_ATI_map_object_buffer                           
      GL_ATI_meminfo                                     
      GL_ATI_pixel_format_float                          
      GL_ATI_pn_triangles                                
      GL_ATI_point_cull_mode                             
      GL_ATI_separate_stencil                            
      GL_ATI_shader_texture_lod                          
      GL_ATI_text_fragment_shader                        
      GL_ATI_texture_compression_3dc                     
      GL_ATI_texture_env_combine3                        
      GL_ATI_texture_float                              
      GL_ATI_texture_mirror_once                        
      GL_ATI_vertex_array_object                         
      GL_ATI_vertex_attrib_array_object                  
      GL_ATI_vertex_blend                                
      GL_ATI_vertex_shader                               
      GL_ATI_vertex_streams                              
      GL_ATIX_pn_triangles                               
      GL_ATIX_texture_env_combine3                       
      GL_ATIX_texture_env_route                          
      GL_ATIX_vertex_shader_output_point_size            
      GL_Autodesk_facet_normal                           
      GL_Autodesk_valid_back_buffer_hint                 
      GL_DIMD_YUV                                        
      GL_EXT_422_pixels                                  
      GL_EXT_abgr                                       
      GL_EXT_bgra                                       
      GL_EXT_bindable_uniform                           
      GL_EXT_blend_color                                
      GL_EXT_blend_equation_separate                    
      GL_EXT_blend_func_separate                        
      GL_EXT_blend_logic_op                              
      GL_EXT_blend_minmax                               
      GL_EXT_blend_subtract                             
      GL_EXT_Cg_shader                                  
      GL_EXT_clip_volume_hint                            
      GL_EXT_cmyka                                       
      GL_EXT_color_matrix                                
      GL_EXT_color_subtable                              
      GL_EXT_color_table                                 
      GL_EXT_compiled_vertex_array                      
      GL_EXT_convolution                                 
      GL_EXT_convolution_border_modes                    
      GL_EXT_coordinate_frame                            
      GL_EXT_copy_buffer                                 
      GL_EXT_copy_texture                                
      GL_EXT_cull_vertex                                 
      GL_EXT_depth_bounds_test                          
      GL_EXT_depth_buffer_float                          
      GL_EXT_direct_state_access                        
      GL_EXT_draw_buffers2                              
      GL_EXT_draw_indirect                               
      GL_EXT_draw_instanced                             
      GL_EXT_draw_range_elements                        
      GL_EXT_fog_coord                                  
      GL_EXT_fog_function                                
      GL_EXT_fog_offset                                  
      GL_EXT_fragment_lighting                           
      GL_EXT_framebuffer_blit                           
      GL_EXT_framebuffer_multisample                    
      GL_EXT_framebuffer_object                         
      GL_EXT_framebuffer_sRGB                           
      GL_EXT_generate_mipmap                             
      GL_EXT_geometry_shader4                           
      GL_EXT_gpu_program_parameters                     
      GL_EXT_gpu_shader_fp64                             
      GL_EXT_gpu_shader4                                
      GL_EXT_gpu_shader5                                 
      GL_EXT_histogram                                   
      GL_EXT_import_sync_object                         
      GL_EXT_index_array_formats                         
      GL_EXT_index_func                                  
      GL_EXT_index_material                              
      GL_EXT_index_texture                               
      GL_EXT_interlace                                   
      GL_EXT_light_texture                               
      GL_EXT_misc_attribute                              
      GL_EXT_multi_draw_arrays                          
      GL_EXT_multisample                                 
      GL_EXT_packed_depth_stencil                       
      GL_EXT_packed_float                               
      GL_EXT_packed_pixels                              
      GL_EXT_packed_pixels_12                            
      GL_EXT_paletted_texture                            
      GL_EXT_pixel_buffer_object                        
      GL_EXT_pixel_format                                
      GL_EXT_pixel_texture                               
      GL_EXT_pixel_transform                             
      GL_EXT_pixel_transform_color_table                 
      GL_EXT_point_parameters                           
      GL_EXT_polygon_offset                              
      GL_EXT_provoking_vertex                           
      GL_EXT_rescale_normal                             
      GL_EXT_scene_marker                                
      GL_EXT_secondary_color                            
      GL_EXT_separate_shader_objects                    
      GL_EXT_separate_specular_color                    
      GL_EXT_shader_atomic_counters                      
      GL_EXT_shader_image_load_store                    
      GL_EXT_shader_subroutine                           
      GL_EXT_shadow_funcs                               
      GL_EXT_shared_texture_palette                      
      GL_EXT_stencil_clear_tag                           
      GL_EXT_stencil_two_side                           
      GL_EXT_stencil_wrap                               
      GL_EXT_subtexture                                  
      GL_EXT_swap_control                                
      GL_EXT_tessellation_shader                         
      GL_EXT_texgen_reflection                           
      GL_EXT_texture                                     
      GL_EXT_texture_array                              
      GL_EXT_texture_border_clamp                        
      GL_EXT_texture_buffer_object                      
      GL_EXT_texture_buffer_object_rgb32                 
      GL_EXT_texture_color_table                         
      GL_EXT_texture_compression_bptc                    
      GL_EXT_texture_compression_dxt1                   
      GL_EXT_texture_compression_latc                   
      GL_EXT_texture_compression_rgtc                   
      GL_EXT_texture_compression_s3tc                   
      GL_EXT_texture_cube_map                           
      GL_EXT_texture_edge_clamp                         
      GL_EXT_texture_env                                 
      GL_EXT_texture_env_add                            
      GL_EXT_texture_env_combine                        
      GL_EXT_texture_env_dot3                           
      GL_EXT_texture_filter_anisotropic                 
      GL_EXT_texture_format_BGRA8888                    
      GL_EXT_texture_integer                            
      GL_EXT_texture_lod                                
      GL_EXT_texture_lod_bias                           
      GL_EXT_texture_mirror_clamp                       
      GL_EXT_texture_object                             
      GL_EXT_texture_perturb_normal                      
      GL_EXT_texture_rectangle                           
      GL_EXT_texture_shared_exponent                    
      GL_EXT_texture_snorm                               
      GL_EXT_texture_sRGB                               
      GL_EXT_texture_sRGB_decode                        
      GL_EXT_texture_storage                            
      GL_EXT_texture_swizzle                            
      GL_EXT_texture_type_2_10_10_10_REV                
      GL_EXT_texture3D                                  
      GL_EXT_texture4D                                   
      GL_EXT_timer_query                                
      GL_EXT_transform_feedback                          
      GL_EXT_transform_feedback2                        
      GL_EXT_transform_feedback3                         
      GL_EXT_vertex_array                               
      GL_EXT_vertex_array_bgra                          
      GL_EXT_vertex_attrib_64bit                        
      GL_EXT_vertex_shader                               
      GL_EXT_vertex_weighting                            
      GL_EXTX_framebuffer_mixed_formats                 
      GL_EXTX_packed_depth_stencil                       
      GL_FGL_lock_texture                                
      GL_GL2_geometry_shader                             
      GL_GREMEDY_frame_terminator                        
      GL_GREMEDY_string_marker                           
      GL_HP_convolution_border_modes                     
      GL_HP_image_transform                              
      GL_HP_occlusion_test                               
      GL_HP_texture_lighting                             
      GL_I3D_argb                                        
      GL_I3D_color_clamp                                 
      GL_I3D_interlace_read                              
      GL_IBM_clip_check                                  
      GL_IBM_cull_vertex                                 
      GL_IBM_load_named_matrix                           
      GL_IBM_multi_draw_arrays                           
      GL_IBM_multimode_draw_arrays                       
      GL_IBM_occlusion_cull                              
      GL_IBM_pixel_filter_hint                           
      GL_IBM_rasterpos_clip                             
      GL_IBM_rescale_normal                              
      GL_IBM_static_data                                 
      GL_IBM_texture_clamp_nodraw                        
      GL_IBM_texture_mirrored_repeat                    
      GL_IBM_vertex_array_lists                          
      GL_IBM_YCbCr                                       
      GL_IMG_read_format                                 
      GL_IMG_texture_compression_pvrtc                   
      GL_IMG_texture_env_enhanced_fixed_function         
      GL_IMG_texture_format_BGRA8888                     
      GL_IMG_user_clip_planes                            
      GL_IMG_vertex_program                              
      GL_INGR_blend_func_separate                        
      GL_INGR_color_clamp                                
      GL_INGR_interlace_read                             
      GL_INGR_multiple_palette                           
      GL_INTEL_parallel_arrays                           
      GL_INTEL_texture_scissor                           
      GL_KTX_buffer_region                              
      GL_MESA_pack_invert                                
      GL_MESA_program_debug                              
      GL_MESA_resize_buffers                             
      GL_MESA_window_pos                                 
      GL_MESA_ycbcr_texture                              
      GL_MESAX_texture_stack                             
      GL_MTX_fragment_shader                             
      GL_MTX_precision_dpi                               
      GL_NV_alpha_test                                  
      GL_NV_blend_minmax                                
      GL_NV_blend_square                                
      GL_NV_centroid_sample                              
      GL_NV_complex_primitives                          
      GL_NV_conditional_render                          
      GL_NV_copy_depth_to_color                         
      GL_NV_copy_image                                  
      GL_NV_depth_buffer_float                          
      GL_NV_depth_clamp                                 
      GL_NV_depth_range_unclamped                        
      GL_NV_evaluators                                   
      GL_NV_explicit_multisample                        
      GL_NV_fbo_color_attachments                       
      GL_NV_fence                                       
      GL_NV_float_buffer                                
      GL_NV_fog_distance                                
      GL_NV_fragdepth                                   
      GL_NV_fragment_program                            
      GL_NV_fragment_program_option                     
      GL_NV_fragment_program2                           
      GL_NV_fragment_program4                            
      GL_NV_framebuffer_multisample_coverage            
      GL_NV_framebuffer_multisample_ex                   
      GL_NV_geometry_program4                            
      GL_NV_geometry_shader4                            
      GL_NV_gpu_program_fp64                            
      GL_NV_gpu_program4                                
      GL_NV_gpu_program4_1                              
      GL_NV_gpu_program5                                
      GL_NV_gpu_shader5                                 
      GL_NV_half_float                                  
      GL_NV_light_max_exponent                          
      GL_NV_multisample_coverage                        
      GL_NV_multisample_filter_hint                     
      GL_NV_occlusion_query                             
      GL_NV_packed_depth_stencil                        
      GL_NV_parameter_buffer_object                     
      GL_NV_parameter_buffer_object2                    
      GL_NV_path_rendering                              
      GL_NV_pixel_buffer_object                          
      GL_NV_pixel_data_range                            
      GL_NV_point_sprite                                
      GL_NV_present_video                                
      GL_NV_primitive_restart                           
      GL_NV_register_combiners                          
      GL_NV_register_combiners2                         
      GL_NV_shader_atomic_counters                      
      GL_NV_shader_buffer_load                          
      GL_NV_shader_buffer_store                          
      GL_NV_tessellation_program5                        
      GL_NV_texgen_emboss                                
      GL_NV_texgen_reflection                           
      GL_NV_texture_barrier                             
      GL_NV_texture_compression_latc                     
      GL_NV_texture_compression_vtc                     
      GL_NV_texture_env_combine4                        
      GL_NV_texture_expand_normal                       
      GL_NV_texture_lod_clamp                           
      GL_NV_texture_multisample                         
      GL_NV_texture_rectangle                           
      GL_NV_texture_shader                              
      GL_NV_texture_shader2                             
      GL_NV_texture_shader3                             
      GL_NV_timer_query                                  
      GL_NV_transform_feedback                          
      GL_NV_transform_feedback2                         
      GL_NV_vdpau_interop                                
      GL_NV_vertex_array_range                          
      GL_NV_vertex_array_range2                         
      GL_NV_vertex_attrib_64bit                          
      GL_NV_vertex_attrib_integer_64bit                 
      GL_NV_vertex_buffer_unified_memory                
      GL_NV_vertex_program                              
      GL_NV_vertex_program1_1                           
      GL_NV_vertex_program2                             
      GL_NV_vertex_program2_option                      
      GL_NV_vertex_program3                             
      GL_NV_vertex_program4                              
      GL_NVX_conditional_render                         
      GL_NVX_flush_hold                                  
      GL_NVX_gpu_memory_info                            
      GL_NVX_instanced_arrays                            
      GL_NVX_ycrcb                                       
      GL_OES_blend_subtract                              
      GL_OES_byte_coordinates                            
      GL_OES_compressed_paletted_texture                 
      GL_OES_conditional_query                           
      GL_OES_depth_texture                              
      GL_OES_depth24                                    
      GL_OES_depth32                                    
      GL_OES_draw_texture                                
      GL_OES_element_index_uint                         
      GL_OES_fbo_render_mipmap                          
      GL_OES_fixed_point                                 
      GL_OES_framebuffer_object                          
      GL_OES_get_program_binary                         
      GL_OES_mapbuffer                                  
      GL_OES_matrix_get                                  
      GL_OES_matrix_palette                              
      GL_OES_packed_depth_stencil                       
      GL_OES_point_size_array                            
      GL_OES_point_sprite                                
      GL_OES_query_matrix                                
      GL_OES_read_format                                 
      GL_OES_rgb8_rgba8                                 
      GL_OES_single_precision                            
      GL_OES_standard_derivatives                       
      GL_OES_texture_3D                                 
      GL_OES_texture_float                              
      GL_OES_texture_float_linear                       
      GL_OES_texture_half_float                         
      GL_OES_texture_half_float_linear                  
      GL_OES_texture_mirrored_repeat                     
      GL_OES_texture_npot                               
      GL_OES_vertex_array_object                        
      GL_OES_vertex_half_float                          
      GL_OML_interlace                                   
      GL_OML_resample                                    
      GL_OML_subsample                                   
      GL_PGI_misc_hints                                  
      GL_PGI_vertex_hints                                
      GL_REND_screen_coordinates                         
      GL_S3_performance_analyzer                         
      GL_S3_s3tc                                        
      GL_SGI_color_matrix                                
      GL_SGI_color_table                                 
      GL_SGI_compiled_vertex_array                       
      GL_SGI_cull_vertex                                 
      GL_SGI_index_array_formats                         
      GL_SGI_index_func                                  
      GL_SGI_index_material                              
      GL_SGI_index_texture                               
      GL_SGI_make_current_read                           
      GL_SGI_texture_add_env                             
      GL_SGI_texture_color_table                         
      GL_SGI_texture_edge_clamp                          
      GL_SGI_texture_lod                                 
      GL_SGIS_color_range                                
      GL_SGIS_detail_texture                             
      GL_SGIS_fog_function                               
      GL_SGIS_generate_mipmap                           
      GL_SGIS_multisample                                
      GL_SGIS_multitexture                               
      GL_SGIS_pixel_texture                              
      GL_SGIS_point_line_texgen                          
      GL_SGIS_sharpen_texture                            
      GL_SGIS_texture_border_clamp                       
      GL_SGIS_texture_color_mask                         
      GL_SGIS_texture_edge_clamp                         
      GL_SGIS_texture_filter4                            
      GL_SGIS_texture_lod                               
      GL_SGIS_texture_select                             
      GL_SGIS_texture4D                                  
      GL_SGIX_async                                      
      GL_SGIX_async_histogram                            
      GL_SGIX_async_pixel                                
      GL_SGIX_blend_alpha_minmax                         
      GL_SGIX_clipmap                                    
      GL_SGIX_convolution_accuracy                       
      GL_SGIX_depth_pass_instrument                      
      GL_SGIX_depth_texture                             
      GL_SGIX_flush_raster                               
      GL_SGIX_fog_offset                                 
      GL_SGIX_fog_texture                                
      GL_SGIX_fragment_specular_lighting                 
      GL_SGIX_framezoom                                  
      GL_SGIX_instruments                                
      GL_SGIX_interlace                                  
      GL_SGIX_ir_instrument1                             
      GL_SGIX_list_priority                              
      GL_SGIX_pbuffer                                    
      GL_SGIX_pixel_texture                              
      GL_SGIX_pixel_texture_bits                         
      GL_SGIX_reference_plane                            
      GL_SGIX_resample                                   
      GL_SGIX_shadow                                    
      GL_SGIX_shadow_ambient                             
      GL_SGIX_sprite                                     
      GL_SGIX_subsample                                  
      GL_SGIX_tag_sample_buffer                          
      GL_SGIX_texture_add_env                            
      GL_SGIX_texture_coordinate_clamp                   
      GL_SGIX_texture_lod_bias                           
      GL_SGIX_texture_multi_buffer                       
      GL_SGIX_texture_range                              
      GL_SGIX_texture_scale_bias                         
      GL_SGIX_vertex_preclip                             
      GL_SGIX_vertex_preclip_hint                        
      GL_SGIX_ycrcb                                      
      GL_SGIX_ycrcb_subsample                            
      GL_SUN_convolution_border_modes                    
      GL_SUN_global_alpha                                
      GL_SUN_mesh_array                                  
      GL_SUN_multi_draw_arrays                           
      GL_SUN_read_video_pixels                           
      GL_SUN_slice_accum                                
      GL_SUN_triangle_list                               
      GL_SUN_vertex                                      
      GL_SUNX_constant_data                              
      GL_WGL_ARB_extensions_string                       
      GL_WGL_EXT_extensions_string                       
      GL_WGL_EXT_swap_control                            
      GL_WIN_phong_shading                               
      GL_WIN_specular_fog                                
      GL_WIN_swap_hint                                  
      GLU_EXT_nurbs_tessellator                          
      GLU_EXT_object_space_tess                          
      GLU_SGI_filter4_parameters                         
      GLX_ARB_create_context                             
      GLX_ARB_fbconfig_float                             
      GLX_ARB_framebuffer_sRGB                           
      GLX_ARB_get_proc_address                           
      GLX_ARB_multisample                                
      GLX_EXT_fbconfig_packed_float                      
      GLX_EXT_framebuffer_sRGB                           
      GLX_EXT_import_context                             
      GLX_EXT_scene_marker                               
      GLX_EXT_texture_from_pixmap                        
      GLX_EXT_visual_info                                
      GLX_EXT_visual_rating                              
      GLX_MESA_agp_offset                                
      GLX_MESA_copy_sub_buffer                           
      GLX_MESA_pixmap_colormap                           
      GLX_MESA_release_buffers                           
      GLX_MESA_set_3dfx_mode                             
      GLX_NV_present_video                               
      GLX_NV_swap_group                                  
      GLX_NV_video_output                                
      GLX_OML_swap_method                                
      GLX_OML_sync_control                               
      GLX_SGI_cushion                                    
      GLX_SGI_make_current_read                          
      GLX_SGI_swap_control                               
      GLX_SGI_video_sync                                 
      GLX_SGIS_blended_overlay                           
      GLX_SGIS_color_range                               
      GLX_SGIS_multisample                               
      GLX_SGIX_dm_buffer                                 
      GLX_SGIX_fbconfig                                  
      GLX_SGIX_hyperpipe                                 
      GLX_SGIX_pbuffer                                   
      GLX_SGIX_swap_barrier                              
      GLX_SGIX_swap_group                                
      GLX_SGIX_video_resize                              
      GLX_SGIX_video_source                              
      GLX_SGIX_visual_select_group                       
      GLX_SUN_get_transparent_index                      
      GLX_SUN_video_resize                               
      WGL_3DFX_gamma_control                             
      WGL_3DFX_multisample                               
      WGL_3DL_stereo_control                             
      WGL_AMD_gpu_association                            
      WGL_AMDX_gpu_association                           
      WGL_ARB_buffer_region                             
      WGL_ARB_create_context                            
      WGL_ARB_create_context_profile                    
      WGL_ARB_create_context_robustness                 
      WGL_ARB_extensions_string                         
      WGL_ARB_framebuffer_sRGB                           
      WGL_ARB_make_current_read                         
      WGL_ARB_multisample                               
      WGL_ARB_pbuffer                                   
      WGL_ARB_pixel_format                              
      WGL_ARB_pixel_format_float                        
      WGL_ARB_render_texture                            
      WGL_ATI_pbuffer_memory_hint                        
      WGL_ATI_pixel_format_float                        
      WGL_ATI_render_texture_rectangle                   
      WGL_EXT_buffer_region                              
      WGL_EXT_create_context_es2_profile                
      WGL_EXT_depth_float                                
      WGL_EXT_display_color_table                        
      WGL_EXT_extensions_string                         
      WGL_EXT_framebuffer_sRGB                          
      WGL_EXT_framebuffer_sRGBWGL_ARB_create_context     
      WGL_EXT_gamma_control                              
      WGL_EXT_make_current_read                          
      WGL_EXT_multisample                                
      WGL_EXT_pbuffer                                    
      WGL_EXT_pixel_format                               
      WGL_EXT_pixel_format_packed_float                 
      WGL_EXT_render_texture                             
      WGL_EXT_swap_control                              
      WGL_EXT_swap_interval                              
      WGL_I3D_digital_video_control                      
      WGL_I3D_gamma                                      
      WGL_I3D_genlock                                    
      WGL_I3D_image_buffer                               
      WGL_I3D_swap_frame_lock                            
      WGL_I3D_swap_frame_usage                           
      WGL_MTX_video_preview                              
      WGL_NV_copy_image                                  
      WGL_NV_DX_interop                                 
      WGL_NV_DX_interop2                                
      WGL_NV_float_buffer                               
      WGL_NV_gpu_affinity                                
      WGL_NV_multisample_coverage                       
      WGL_NV_present_video                               
      WGL_NV_render_depth_texture                       
      WGL_NV_render_texture_rectangle                   
      WGL_NV_swap_group                                  
      WGL_NV_vertex_array_range                          
      WGL_NV_video_output                                
      WGL_NVX_DX_interop                                
      WGL_OML_sync_control                               

       :
      RGB DXT1                                          
      RGBA DXT1                                          
      RGBA DXT3                                         
      RGBA DXT5                                         
      RGB FXT1                                           
      RGBA FXT1                                          
      3Dc                                                

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[ GPGPU ]-------------------------------------------------------------------------------------------------------

  [ CUDA: GeForce GTX 580 ]

     :
                                           GeForce GTX 580
                                                 1544 
      /                             16 / 512
      Max Threads Per Block                             1024
      Max Registers Per Block                           32768
      Warp Size                                         32 threads
      Max Block Size                                    1024 x 1024 x 64
      Max Grid Size                                     65535 x 65535 x 65535
      Max 1D Texture Width                              65536
      Max 2D Texture Size                               65536 x 65535
      Max 3D Texture Size                               2048 x 2048 x 2048
      Max Texture Array Size                            16384 x 16384
      Max Texture Array Slices                          2048
      Compute Mode                                      Default: Multiple contexts allowed per device
      Compute Capability                                2.0
      CUDA DLL                                          nvcuda.dll (8.17.12.8562 - nVIDIA ForceWare 285.62)

     :
      Total Memory                                      1536 
      Total Constant Memory                             64 
      Max Shared Memory Per Block                       48 
      Max Memory Pitch                                  2147483647 
      Texture Alignment                                 512 
      Surface Alignment                                 512 

     :
      32-bit Floating-Point Atomic Addition             
      32-bit Integer Atomic Operations                  
      64-bit Integer Atomic Operations                  
      Concurrent Kernel Execution                       
      Concurrent Memory Copy & Execute                  
      Double-Precision Floating-Point                   
      ECC                                               
      Host Memory Mapping                               
      Integrated Device                                 
      Warp Vote Functions                               
      __ballot()                                        
      __syncthreads_and()                               
      __syncthreads_count()                             
      __syncthreads_or()                                
      __threadfence_system()                            

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ Direct3D: NVIDIA GeForce GTX 580 ]

     :
                                           NVIDIA GeForce GTX 580
                                             nvd3dum.dll
                                          8.17.12.8562 - nVIDIA ForceWare 285.62
      Shader Model                                      SM 5.0
      Max Threads                                       1024
      Multiple UAV Access                               8 UAVs
      Thread Dispatch                                   3D
      Thread Local Storage                              32 

     :
      Append/Consume Buffers                            
      Atomic Operations                                 
      Double-Precision Floating-Point                   
      Gather4                                           
      Indirect Compute Dispatch                         

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ OpenCL: GeForce GTX 580 ]

    OpenCL Properties:
      Platform Name                                     NVIDIA CUDA
      Platform Vendor                                   NVIDIA Corporation
      Platform Version                                  OpenCL 1.1 CUDA 4.1.1
      Platform Profile                                  Full

     :
                                           GeForce GTX 580
                                            
      Device Vendor                                     NVIDIA Corporation
      Device Version                                    OpenCL 1.1 CUDA
      Device Profile                                    Full
                                                 1544 
      Multiprocessors                                   16
      Max 2D Image Size                                 32768 x 32768
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Samplers                                      16
      Max Work-Item Size                                1024 x 1024 x 64
      Max Work-Group Size                               1024
      Max Argument Size                                 4352 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            9
      Profiling Timer Resolution                        1000 ns
      OpenCL DLL                                        opencl.dll (1.0.0)

     :
      Global Memory                                     1536 
      Global Memory Cache                               256   (Read/Write, 128-byte line)
      Local Memory                                      48 
      Memory Base Address Alignment                     4096 
      Min Data Type Alignment                           128 

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler                                          
                                          
      Images                                            
      Kernel Execution                                  
      Native Kernel Execution                            

    Device Extensions:
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                      
      cl_amd_fp64                                        
      cl_amd_media_ops                                   
      cl_amd_printf                                      
      cl_khr_3d_image_writes                             
      cl_khr_byte_addressable_store                     
      cl_khr_d3d10_sharing                              
      cl_khr_fp16                                        
      cl_khr_fp64                                       
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                        
      cl_khr_int64_base_atomics                          
      cl_khr_int64_extended_atomics                      
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_select_fprounding_mode                      
      cl_nv_compiler_options                            
      cl_nv_d3d10_sharing                               
      cl_nv_d3d11_sharing                               
      cl_nv_d3d9_sharing                                
      cl_nv_device_attribute_query                      
      cl_nv_pragma_unroll                               

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[  ]------------------------------------------------------------------------------------------------------

    @Batang                                   Roman       Regular                      16 x 32   40 %
    @Batang                                   Roman       Regular                       16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                   16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                         16 x 32   40 %
    @Batang                                   Roman       Regular           16 x 32   40 %
    @BatangChe                                Modern      Regular                      16 x 32   40 %
    @BatangChe                                Modern      Regular                       16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                   16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                         16 x 32   40 %
    @BatangChe                                Modern      Regular           16 x 32   40 %
    @DFKai-SB                                 Script      Regular                        16 x 32   40 %
    @DFKai-SB                                 Script      Regular         (BIG5)        16 x 32   40 %
    @Dotum                                    Swiss       Regular                      16 x 32   40 %
    @Dotum                                    Swiss       Regular                       16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                   16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                         16 x 32   40 %
    @Dotum                                    Swiss       Regular           16 x 32   40 %
    @DotumChe                                 Modern      Regular                      16 x 32   40 %
    @DotumChe                                 Modern      Regular                       16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                   16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                         16 x 32   40 %
    @DotumChe                                 Modern      Regular           16 x 32   40 %
    @FangSong                                 Modern                              16 x 32   40 %
    @FangSong                                 Modern               (2312)        16 x 32   40 %
    @Gulim                                    Swiss       Regular                      16 x 32   40 %
    @Gulim                                    Swiss       Regular                       16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                   16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                         16 x 32   40 %
    @Gulim                                    Swiss       Regular           16 x 32   40 %
    @GulimChe                                 Modern      Regular                      16 x 32   40 %
    @GulimChe                                 Modern      Regular                       16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                   16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                         16 x 32   40 %
    @GulimChe                                 Modern      Regular           16 x 32   40 %
    @Gungsuh                                  Roman       Regular                      16 x 32   40 %
    @Gungsuh                                  Roman       Regular                       16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                   16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                         16 x 32   40 %
    @Gungsuh                                  Roman       Regular           16 x 32   40 %
    @GungsuhChe                               Modern      Regular                      16 x 32   40 %
    @GungsuhChe                               Modern      Regular                       16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                   16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                         16 x 32   40 %
    @GungsuhChe                               Modern      Regular           16 x 32   40 %
    @KaiTi                                    Modern                              16 x 32   40 %
    @KaiTi                                    Modern               (2312)        16 x 32   40 %
    @Malgun Gothic                            Swiss       Regular                        15 x 43   40 %
    @Malgun Gothic                            Swiss       Regular                         15 x 43   40 %
    @Meiryo UI                                Swiss                             17 x 41   40 %
    @Meiryo UI                                Swiss                              17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                          17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                  17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo                                   Swiss                             31 x 48   40 %
    @Meiryo                                   Swiss                              31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                          31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                  31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Microsoft JhengHei                       Swiss                              15 x 43   40 %
    @Microsoft JhengHei                       Swiss                               15 x 43   40 %
    @Microsoft JhengHei                       Swiss                (BIG5)        15 x 43   40 %
    @Microsoft YaHei                          Swiss                              15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                          15 x 42   40 %
    @Microsoft YaHei                          Swiss                (2312)        15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                  15 x 42   40 %
    @MingLiU                                  Modern      Regular                        16 x 32   40 %
    @MingLiU                                  Modern      Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    @MS Gothic                                Modern      Regular                      16 x 32   40 %
    @MS Gothic                                Modern      Regular                       16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular                   16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular           16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                      16 x 32   40 %
    @MS Mincho                                Modern      Regular                       16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                   16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular           16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS PGothic                               Swiss       Regular                      13 x 32   40 %
    @MS PGothic                               Swiss       Regular                       13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular                   13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular           13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                      13 x 32   40 %
    @MS PMincho                               Roman       Regular                       13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                   13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular           13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                      13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                       13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                   13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular           13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @NSimSun                                  Modern      Regular                        16 x 32   40 %
    @NSimSun                                  Modern      Regular         (2312)        16 x 32   40 %
    @PMingLiU                                 Roman       Regular                        16 x 32   40 %
    @PMingLiU                                 Roman       Regular         (BIG5)        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular                        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular         (BIG5)        16 x 32   40 %
    @SimHei                                   Modern                              16 x 32   40 %
    @SimHei                                   Modern               (2312)        16 x 32   40 %
    @SimSun                                   Special     Regular                        16 x 32   40 %
    @SimSun                                   Special     Regular         (2312)        16 x 32   40 %
    @SimSun-ExtB                              Modern                              16 x 32   40 %
    @SimSun-ExtB                              Modern               (2312)        16 x 32   40 %
    Aharoni                                   Special                             15 x 32   70 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Angsana New                               Roman                                8 x 43   40 %
    Angsana New                               Roman                                 8 x 43   40 %
    AngsanaUPC                                Roman                                8 x 43   40 %
    AngsanaUPC                                Roman                                 8 x 43   40 %
    Aparajita                                 Swiss       Regular                        16 x 38   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                             9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                  9 x 36   40 %
    Arial Black                               Swiss                             18 x 45   90 %
    Arial Black                               Swiss                              18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                          18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                  18 x 45   90 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                             14 x 36   40 %
    Arial                                     Swiss                            14 x 36   40 %
    Arial                                     Swiss                              14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                                  14 x 36   40 %
    Arial                                     Swiss                          14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                  14 x 36   40 %
    BankGothic Lt BT                          Swiss       Light                         18 x 33   40 %
    BankGothic Lt BT                          Swiss       Light                          18 x 33   40 %
    BankGothic Lt BT                          Swiss       Light                          18 x 33   40 %
    BankGothic Lt BT                          Swiss       Light                          18 x 33   40 %
    BankGothic Lt BT                          Swiss       Light             18 x 33   40 %
    Batang                                    Roman       Regular                      16 x 32   40 %
    Batang                                    Roman       Regular                       16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                   16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                         16 x 32   40 %
    Batang                                    Roman       Regular           16 x 32   40 %
    BatangChe                                 Modern      Regular                      16 x 32   40 %
    BatangChe                                 Modern      Regular                       16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                   16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                         16 x 32   40 %
    BatangChe                                 Modern      Regular           16 x 32   40 %
    Browallia New                             Swiss       Regular                         9 x 40   40 %
    Browallia New                             Swiss       Regular                          9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                         9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                          9 x 40   40 %
    Calibri                                   Swiss       Regular                      17 x 39   40 %
    Calibri                                   Swiss       Regular                     17 x 39   40 %
    Calibri                                   Swiss       Regular                       17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular                   17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular           17 x 39   40 %
    Cambria Math                              Roman       Regular                      20 x 179   40 %
    Cambria Math                              Roman       Regular                     20 x 179   40 %
    Cambria Math                              Roman       Regular                       20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular                   20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular           20 x 179   40 %
    Cambria                                   Roman       Regular                      20 x 40   40 %
    Cambria                                   Roman       Regular                     20 x 40   40 %
    Cambria                                   Roman       Regular                       20 x 40   40 %
    Cambria                                   Roman       Regular                        20 x 40   40 %
    Cambria                                   Roman       Regular                   20 x 40   40 %
    Cambria                                   Roman       Regular                        20 x 40   40 %
    Cambria                                   Roman       Regular           20 x 40   40 %
    Candara                                   Swiss       Regular                      17 x 39   40 %
    Candara                                   Swiss       Regular                     17 x 39   40 %
    Candara                                   Swiss       Regular                       17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular                   17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular           17 x 39   40 %
    Comic Sans MS                             Script                            15 x 45   40 %
    Comic Sans MS                             Script                             15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                         15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                 15 x 45   40 %
    Consolas                                  Modern      Regular                      18 x 37   40 %
    Consolas                                  Modern      Regular                     18 x 37   40 %
    Consolas                                  Modern      Regular                       18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular                   18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular           18 x 37   40 %
    Constantia                                Roman       Regular                      17 x 39   40 %
    Constantia                                Roman       Regular                     17 x 39   40 %
    Constantia                                Roman       Regular                       17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular                   17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular           17 x 39   40 %
    Corbel                                    Swiss       Regular                      17 x 39   40 %
    Corbel                                    Swiss       Regular                     17 x 39   40 %
    Corbel                                    Swiss       Regular                       17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular                   17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular           17 x 39   40 %
    Cordia New                                Swiss       Regular                         9 x 44   40 %
    Cordia New                                Swiss       Regular                          9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                         9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                          9 x 44   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                            19 x 36   40 %
    Courier New                               Modern                           19 x 36   40 %
    Courier New                               Modern                             19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                                 19 x 36   40 %
    Courier New                               Modern                         19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                 19 x 36   40 %
    Courier                                   Roman                                  8 x 13   40 %
    DaunPenh                                  Special                             12 x 43   40 %
    David                                     Swiss       Regular                           13 x 31   40 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                 16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                  16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                   16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                      16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique              16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                   16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique      16 x 37   70 %
    DejaVu Sans Light                         Swiss       ExtraLight                   16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                  16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                    16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                     16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                     16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight        16 x 37   20 %
    DejaVu Sans Mono                          Modern      Oblique                      19 x 37   40 %
    DejaVu Sans Mono                          Modern      Oblique                       19 x 37   40 %
    DejaVu Sans Mono                          Modern      Oblique                        19 x 37   40 %
    DejaVu Sans Mono                          Modern      Oblique                   19 x 37   40 %
    DejaVu Sans Mono                          Modern      Oblique                        19 x 37   40 %
    DejaVu Sans Mono                          Modern      Oblique           19 x 37   40 %
    DejaVu Sans                               Swiss       Book                           16 x 37   40 %
    DejaVu Sans                               Swiss       Book                         16 x 37   40 %
    DejaVu Sans                               Swiss       Book                        16 x 37   40 %
    DejaVu Sans                               Swiss       Book                          16 x 37   40 %
    DejaVu Sans                               Swiss       Book                           16 x 37   40 %
    DejaVu Sans                               Swiss       Book                              16 x 37   40 %
    DejaVu Sans                               Swiss       Book                      16 x 37   40 %
    DejaVu Sans                               Swiss       Book                         16 x 37   40 %
    DejaVu Sans                               Swiss       Book                           16 x 37   40 %
    DejaVu Sans                               Swiss       Book              16 x 37   40 %
    DejaVu Serif Condensed                    Roman       Bold                         16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold                          16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold                           16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold                      16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold                           16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold              16 x 38   70 %
    DejaVu Serif                              Roman       Bold                         18 x 38   70 %
    DejaVu Serif                              Roman       Bold                          18 x 38   70 %
    DejaVu Serif                              Roman       Bold                           18 x 38   70 %
    DejaVu Serif                              Roman       Bold                      18 x 38   70 %
    DejaVu Serif                              Roman       Bold                           18 x 38   70 %
    DejaVu Serif                              Roman       Bold              18 x 38   70 %
    DFKai-SB                                  Script      Regular                        16 x 32   40 %
    DFKai-SB                                  Script      Regular         (BIG5)        16 x 32   40 %
    DilleniaUPC                               Roman                                9 x 42   40 %
    DilleniaUPC                               Roman                                 9 x 42   40 %
    DokChampa                                 Swiss                               19 x 62   40 %
    DokChampa                                 Swiss                                19 x 62   40 %
    Dotum                                     Swiss       Regular                      16 x 32   40 %
    Dotum                                     Swiss       Regular                       16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                   16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                         16 x 32   40 %
    Dotum                                     Swiss       Regular           16 x 32   40 %
    DotumChe                                  Modern      Regular                      16 x 32   40 %
    DotumChe                                  Modern      Regular                       16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                   16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                         16 x 32   40 %
    DotumChe                                  Modern      Regular           16 x 32   40 %
    Dungeon                                   Decorative                          18 x 36   40 %
    Ebrima                                    Special                           19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                19 x 43   40 %
    Estrangelo Edessa                         Script                              16 x 36   40 %
    EucrosiaUPC                               Roman                                9 x 39   40 %
    EucrosiaUPC                               Roman                                 9 x 39   40 %
    Euphemia                                  Swiss       Regular                        22 x 42   40 %
    FangSong                                  Modern                              16 x 32   40 %
    FangSong                                  Modern               (2312)        16 x 32   40 %
    Fixedsys                                  Swiss                                  8 x 16   40 %
    Franklin Gothic Medium                    Swiss                             14 x 36   40 %
    Franklin Gothic Medium                    Swiss                              14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                          14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                  14 x 36   40 %
    FrankRuehl                                Swiss       Regular                           13 x 30   40 %
    FreesiaUPC                                Swiss       Regular                         9 x 38   40 %
    FreesiaUPC                                Swiss       Regular                          9 x 38   40 %
    Gabriola                                  Decorative  Regular                      16 x 59   40 %
    Gabriola                                  Decorative  Regular                       16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular                   16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular           16 x 59   40 %
    Gautami                                   Swiss       Regular                        18 x 56   40 %
    Georgia                                   Roman                             14 x 36   40 %
    Georgia                                   Roman                              14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                          14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                  14 x 36   40 %
    Gisha                                     Swiss                               16 x 38   40 %
    Gisha                                     Swiss                                  16 x 38   40 %
    Gulim                                     Swiss       Regular                      16 x 32   40 %
    Gulim                                     Swiss       Regular                       16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                   16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                         16 x 32   40 %
    Gulim                                     Swiss       Regular           16 x 32   40 %
    GulimChe                                  Modern      Regular                      16 x 32   40 %
    GulimChe                                  Modern      Regular                       16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                   16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                         16 x 32   40 %
    GulimChe                                  Modern      Regular           16 x 32   40 %
    Gungsuh                                   Roman       Regular                      16 x 32   40 %
    Gungsuh                                   Roman       Regular                       16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                   16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                         16 x 32   40 %
    Gungsuh                                   Roman       Regular           16 x 32   40 %
    GungsuhChe                                Modern      Regular                      16 x 32   40 %
    GungsuhChe                                Modern      Regular                       16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                   16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                         16 x 32   40 %
    GungsuhChe                                Modern      Regular           16 x 32   40 %
    Impact                                    Swiss                             13 x 39   40 %
    Impact                                    Swiss                              13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                          13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                  13 x 39   40 %
    IrisUPC                                   Swiss       Regular                         9 x 40   40 %
    IrisUPC                                   Swiss       Regular                          9 x 40   40 %
    Iskoola Pota                              Swiss                               22 x 36   40 %
    JasmineUPC                                Roman       Regular                         9 x 34   40 %
    JasmineUPC                                Roman       Regular                          9 x 34   40 %
    KaiTi                                     Modern                              16 x 32   40 %
    KaiTi                                     Modern               (2312)        16 x 32   40 %
    Kalinga                                   Swiss       Regular                        19 x 48   40 %
    Kartika                                   Roman       Regular                        27 x 46   40 %
    Khmer UI                                  Swiss                               21 x 36   40 %
    KodchiangUPC                              Roman       Regular                         9 x 31   40 %
    KodchiangUPC                              Roman       Regular                          9 x 31   40 %
    Kokila                                    Swiss       Regular                        13 x 37   40 %
    Lao UI                                    Swiss                               18 x 43   40 %
    Latha                                     Swiss       Regular                        23 x 44   40 %
    Leelawadee                                Swiss                               17 x 38   40 %
    Leelawadee                                Swiss                                17 x 38   40 %
    Levenim MT                                Special     Regular                           16 x 42   40 %
    LilyUPC                                   Swiss                                9 x 30   40 %
    LilyUPC                                   Swiss                                 9 x 30   40 %
    Lucida Console                            Modern                             19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                         19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                 19 x 32   40 %
    Lucida Sans Unicode                       Swiss                             16 x 49   40 %
    Lucida Sans Unicode                       Swiss                              16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                                  16 x 49   40 %
    Lucida Sans Unicode                       Swiss                          16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                  16 x 49   40 %
    Malgun Gothic                             Swiss       Regular                        15 x 43   40 %
    Malgun Gothic                             Swiss       Regular                         15 x 43   40 %
    Mangal                                    Roman       Regular                        19 x 54   40 %
    Marlett                                   Special     Regular                      31 x 32   50 %
    Meiryo UI                                 Swiss                             17 x 41   40 %
    Meiryo UI                                 Swiss                              17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                          17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                  17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo                                    Swiss                             31 x 48   40 %
    Meiryo                                    Swiss                              31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                          31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                  31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Microsoft Himalaya                        Special                             13 x 32   40 %
    Microsoft JhengHei                        Swiss                              15 x 43   40 %
    Microsoft JhengHei                        Swiss                               15 x 43   40 %
    Microsoft JhengHei                        Swiss                (BIG5)        15 x 43   40 %
    Microsoft New Tai Lue                     Swiss       Regular                        19 x 42   40 %
    Microsoft PhagsPa                         Swiss       Regular                        24 x 41   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                             14 x 36   40 %
    Microsoft Sans Serif                      Swiss                            14 x 36   40 %
    Microsoft Sans Serif                      Swiss                              14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss                          14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                  14 x 36   40 %
    Microsoft Tai Le                          Swiss       Regular                        19 x 41   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft YaHei                           Swiss                              15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                          15 x 42   40 %
    Microsoft YaHei                           Swiss                (2312)        15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                  15 x 42   40 %
    Microsoft Yi Baiti                        Script                              21 x 32   40 %
    MingLiU                                   Modern      Regular                        16 x 32   40 %
    MingLiU                                   Modern      Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular                        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular         (BIG5)        16 x 32   40 %
    Miriam Fixed                              Modern      Regular                           19 x 32   40 %
    Miriam                                    Swiss       Regular                           13 x 32   40 %
    Modern                                    Modern                     OEM/DOS                 19 x 37   40 %
    Mongolian Baiti                           Script                              14 x 34   40 %
    MoolBoran                                 Swiss                               13 x 43   40 %
    MS Gothic                                 Modern      Regular                      16 x 32   40 %
    MS Gothic                                 Modern      Regular                       16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular                   16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular           16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                      16 x 32   40 %
    MS Mincho                                 Modern      Regular                       16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                   16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular           16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS PGothic                                Swiss       Regular                      13 x 32   40 %
    MS PGothic                                Swiss       Regular                       13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular                   13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular           13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                      13 x 32   40 %
    MS PMincho                                Roman       Regular                       13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                   13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular           13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS Sans Serif                             Swiss                                  5 x 13   40 %
    MS Serif                                  Roman                                  5 x 13   40 %
    MS UI Gothic                              Swiss       Regular                      13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                       13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                   13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular           13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MV Boli                                   Special                             18 x 52   40 %
    Narkisim                                  Swiss       Regular                           12 x 32   40 %
    NSimSun                                   Modern      Regular                        16 x 32   40 %
    NSimSun                                   Modern      Regular         (2312)        16 x 32   40 %
    Nyala                                     Special                           18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                18 x 33   40 %
    Old English Text MT                       Script                              12 x 39   40 %
    OpenSymbol                                Special     Regular                        24 x 32   40 %
    Palatino Linotype                         Roman                             14 x 43   40 %
    Palatino Linotype                         Roman                            14 x 43   40 %
    Palatino Linotype                         Roman                              14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                          14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                  14 x 43   40 %
    Plantagenet Cherokee                      Roman                               14 x 41   40 %
    PMingLiU                                  Roman       Regular                        16 x 32   40 %
    PMingLiU                                  Roman       Regular         (BIG5)        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    Raavi                                     Swiss       Regular                        13 x 53   40 %
    Rod                                       Modern      Regular                           19 x 31   40 %
    Roman                                     Roman                      OEM/DOS                 22 x 37   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                           16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                16 x 45   40 %
    Script                                    Script                     OEM/DOS                 16 x 36   40 %
    Segoe Print                               Special     Regular                      21 x 56   40 %
    Segoe Print                               Special     Regular                       21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular                   21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular           21 x 56   40 %
    Segoe Script                              Swiss                             22 x 51   40 %
    Segoe Script                              Swiss                              22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                          22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                  22 x 51   40 %
    Segoe UI Light                            Swiss       Regular                      17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                     17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                       17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                   17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular           17 x 43   30 %
    Segoe UI Semibold                         Swiss       Regular                      18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                     18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                       18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                   18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular           18 x 43   60 %
    Segoe UI Symbol                           Swiss                               23 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                             17 x 43   40 %
    Segoe UI                                  Swiss                            17 x 43   40 %
    Segoe UI                                  Swiss                              17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                          17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                  17 x 43   40 %
    Shonar Bangla                             Swiss       Regular                        16 x 41   40 %
    Shruti                                    Swiss       Regular                        14 x 54   40 %
    SimHei                                    Modern                              16 x 32   40 %
    SimHei                                    Modern               (2312)        16 x 32   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    SimSun                                    Special     Regular                        16 x 32   40 %
    SimSun                                    Special     Regular         (2312)        16 x 32   40 %
    SimSun-ExtB                               Modern                              16 x 32   40 %
    SimSun-ExtB                               Modern               (2312)        16 x 32   40 %
    Small Fonts                               Swiss                                   1 x 3   40 %
    Sylfaen                                   Roman                             13 x 42   40 %
    Sylfaen                                   Roman                              13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                          13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                  13 x 42   40 %
    Symbol                                    Roman                             19 x 39   40 %
    System                                    Swiss                                  7 x 16   70 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                             14 x 39   40 %
    Tahoma                                    Swiss                            14 x 39   40 %
    Tahoma                                    Swiss                              14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                                  14 x 39   40 %
    Tahoma                                    Swiss                          14 x 39   40 %
    Tahoma                                    Swiss                                14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                  14 x 39   40 %
    Tele-Marines                              Special     Regular                        23 x 29   40 %
    Terminal                                  Modern                     OEM/DOS                  8 x 12   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                             13 x 35   40 %
    Times New Roman                           Roman                            13 x 35   40 %
    Times New Roman                           Roman                              13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                                  13 x 35   40 %
    Times New Roman                           Roman                          13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                  13 x 35   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Trebuchet MS                              Swiss                             15 x 37   40 %
    Trebuchet MS                              Swiss                              15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                          15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                  15 x 37   40 %
    Tunga                                     Swiss       Regular                        18 x 53   40 %
    Utsaah                                    Swiss       Regular                        13 x 36   40 %
    Vani                                      Swiss       Regular                        23 x 54   40 %
    Verdana                                   Swiss                             16 x 39   40 %
    Verdana                                   Swiss                            16 x 39   40 %
    Verdana                                   Swiss                              16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                          16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                  16 x 39   40 %
    Vijaya                                    Swiss       Regular                        19 x 32   40 %
    Vrinda                                    Swiss       Regular                        20 x 44   40 %
    Webdings                                  Roman                             31 x 32   40 %
    Wingdings                                 Special     Regular                      28 x 36   40 %


--------[  Windows ]-----------------------------------------------------------------------------------------------

    midi-out.0   0001 001B  Microsoft GS Wavetable Synth
    mixer.0      0001 0068   (SoundMAX Integrated D
    mixer.1      0001 0068   SPDIF (SoundMAX Integ
    mixer.2      0001 0068   (Avnex Virtual Audio D
    mixer.3      0001 0068    (SoundMAX Integr
    mixer.4      0001 0068  .  (SoundMAX Integrated 
    mixer.5      0001 0068   (Avnex Virtual Audio D
    mixer.6      0001 0068   (SoundMAX Integrated D
    wave-in.0    0001 0065   (SoundMAX Integrated D
    wave-in.1    0001 0065  .  (SoundMAX Integrated 
    wave-in.2    0001 0065   (Avnex Virtual Audio D
    wave-out.0   0001 0064   (SoundMAX Integrated D
    wave-out.1   0001 0064   SPDIF (SoundMAX Integ
    wave-out.2   0001 0064   (Avnex Virtual Audio D
    wave-out.3   0001 0064    (SoundMAX Integr


--------[  PCI / PnP ]---------------------------------------------------------------------------------------------

    Analog Devices AD2000B @ Intel 82801JB ICH10 - High Definition Audio Controller   PCI
    nVIDIA HDMI/DP @ nVIDIA GF110 - High Definition Audio Controller                  PCI
    nVIDIA HDMI/DP @ nVIDIA GF110 - High Definition Audio Controller                  PCI
    nVIDIA HDMI/DP @ nVIDIA GF110 - High Definition Audio Controller                  PCI
    nVIDIA HDMI/DP @ nVIDIA GF110 - High Definition Audio Controller                  PCI


--------[ HD Audio ]----------------------------------------------------------------------------------------------------

  [ Intel 82801JB ICH10 - High Definition Audio Controller ]

     :
                                      Intel 82801JB ICH10 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        0 / 27 / 0
      ID                                      8086-3A3E
                               1043-8334
                                                  00
       ID                                     PCI\VEN_8086&DEV_3A3E&SUBSYS_83341043&REV_00

     :
                                                   Intel Corporation
                                     http://www.intel.com/products/chipsets
                                       http://support.intel.com/support/chipsets
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ Analog Devices AD2000B ]

     :
                                      Analog Devices AD2000B
        (Windows)                     SoundMAX Integrated Digital HD Audio
                                           Audio
                                                 HDAUDIO
      ID                                      11D4-989B
                               1043-8334
                                                  1003
       ID                                     HDAUDIO\FUNC_01&VEN_11D4&DEV_989B&SUBSYS_10438334&REV_1003

     :
                                                   Analog Devices, Inc.
                                     http://www.analog.com
                                       http://www.analog.com
                                     http://www.aida64.com/driver-updates

  [ nVIDIA GF110 - High Definition Audio Controller ]

     :
                                      nVIDIA GF110 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        1 / 0 / 1
      ID                                      10DE-0E09
                               19DA-1203
                                                  A1
       ID                                     PCI\VEN_10DE&DEV_0E09&SUBSYS_120319DA&REV_A1

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ nVIDIA HDMI/DP ]

     :
                                      nVIDIA HDMI/DP
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0018
                               10DE-0101
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ nVIDIA HDMI/DP ]

     :
                                      nVIDIA HDMI/DP
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0018
                               10DE-0101
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ nVIDIA HDMI/DP ]

     :
                                      nVIDIA HDMI/DP
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0018
                               10DE-0101
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ nVIDIA HDMI/DP ]

     :
                                      nVIDIA HDMI/DP
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0018
                               10DE-0101
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[ OpenAL ]------------------------------------------------------------------------------------------------------

     OpenAL:
                                           Creative Labs Inc.
      Renderer                                          
                                                  1.1
                                            (SoundMAX Integrated Digital HD Audio)
      OpenAL DLL                                        6.14.0357.24
      Creative OpenAL DLL                               
      Wrapper DLL                                       2.2.0.5
                                62
      X-RAM                                             

     OpenAL:
      AL_EXT_EXPONENT_DISTANCE                          
      AL_EXT_LINEAR_DISTANCE                            
      AL_EXT_OFFSET                                     
      ALC_ENUMERATE_ALL_EXT                             
      ALC_ENUMERATION_EXT                               
      ALC_EXT_CAPTURE                                   
      ALC_EXT_EFX                                       
      EAX                                               
      EAX2.0                                            
      EAX3.0                                            
      EAX3.0EMULATED                                     
      EAX4.0                                            
      EAX4.0EMULATED                                     
      EAX5.0                                             
      EAX-RAM                                            


--------[   ]------------------------------------------------------------------------------------------------

  [ AC-3 ACM Codec ]

      ACM:
                                        AC-3 ACM Codec
      Copyright-                                   2005 by fccHandler
                                  GNU General Public License
                                         Dolby Digital AC-3 codec for Windows ACM
                                          1.06

  [ Fraunhofer IIS MPEG Layer-3 Codec (decode only) ]

      ACM:
                                        Fraunhofer IIS MPEG Layer-3 Codec (decode only)
      Copyright-                                  Copyright  1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS
                                         decoder only version
                                          1.09

  [ Fraunhofer IIS MPEG Layer-3 Codec (professional) ]

      ACM:
                                        Fraunhofer IIS MPEG Layer-3 Codec (professional)
      Copyright-                                  Copyright (C) 1996-2004 Fraunhofer IIS
                                         all bitrates, mono and stereo codec (professional)
                                          3.04

  [ Windows Media Audio ]

      ACM:
                                        Windows Media Audio
      Copyright-                                  Copyright (C) Microsoft Corporation, 1999 - 2001
                                         Compresses and decompresses audio data.
                                          4.02

  [  ADPCM (Microsoft) ]

      ACM:
                                         ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             Microsoft ADPCM.
                                          4.00

  [  CCITT G.711 A-Law  u-Law (Microsoft) ]

      ACM:
                                         CCITT G.711 A-Law  u-Law (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                             CCITT G.711 A-Law / u-Law.
                                          4.00

  [  GSM 6.10 (Microsoft) ]

      ACM:
                                         GSM 6.10 (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                                 ETSI-GSM (European Telecommunications Standards Institute-Groupe Special Mobile)  6.10.
                                          4.00

  [  IMA ADPCM (Microsoft) ]

      ACM:
                                         IMA ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             IMA ADPCM.
                                          4.00

  [  PCM Microsoft ]

      ACM:
                                         PCM Microsoft
      Copyright-                                    , 1992-1996.
                                                PCM.
                                          5.00


--------[   ]------------------------------------------------------------------------------------------------

    ff_vfw.dll                                                     ffdshow video encoder
    frapsvid.dll               3.2.3.11797                         Fraps Video Decompressor
    iccvid.dll                 1.10.0.11                            Cinepak
    iyuv_32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Intel Indeo(R) Video YUV 
    msrle32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Microsoft RLE Compressor
    msvidc32.dll               6.1.7600.16385 (win7_rtm.090713-1255)    Microsoft Video 1
    msyuv.dll                  6.1.7600.16490 (win7_gdr.091218-1705)  Microsoft UYVY Video Decompressor
    tsbyuv.dll                 6.1.7600.16490 (win7_gdr.091218-1705)  Toshiba Video Codec
    wmv9vcm.dll                9.0.1.0369                          Microsoft Windows Media Video 9 VCM
    xvidvfw.dll                                                    Xvid MPEG-4 Video Codec 1.3.2
    yv12vfw.dll                R1.03                               Helix YV12 YUV Codec


--------[ MCI ]---------------------------------------------------------------------------------------------------------

  [ AVIVideo ]

      MCI:
                                              AVIVideo
                                                       Windows
                                                 MCI Video  Windows
                                                     Digital Video Device
                                                 mciavi32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ CDAudio ]

      MCI:
                                              CDAudio
                                                     -
                                                 MCI   cdaudio
                                                     CD Audio Device
                                                 mcicda.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ MPEGVideo ]

      MCI:
                                              MPEGVideo
                                                     DirectShow
                                                 MCI DirectShow
                                                     Digital Video Device
                                                 mciqtz32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ Sequencer ]

      MCI:
                                              Sequencer
                                                      MIDI
                                                 MCI   MIDI
                                                     Sequencer Device
                                                 mciseq.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ WaveAudio ]

      MCI:
                                              WaveAudio
                                                     Sound
                                                 MCI   
                                                     Waveform Audio Device
                                                 mciwave.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          


--------[   Windows ]-------------------------------------------------------------------------------------

  [  ]

     :
                                        
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          flpydisk.inf

  [ WDC WD5000AAKS-22A7B2 ATA Device ]

     :
                                        WDC WD5000AAKS-22A7B2 ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

     :
                                                   Western Digital Corporation
                                     http://www.wdc.com/en

  [ EDQPEB CX2J4HYRKP2B SCSI CdRom Device ]

     :
                                        EDQPEB CX2J4HYRKP2B SCSI CdRom Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cdrom.inf

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

  [ Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26 ]

     :
                                        Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
                                            04.06.2009
                                          9.1.1.1013
                                       Intel
      INF-                                          oem2.inf

     :
      IRQ                                               19
                                                    8400-840F
                                                    8480-848F
                                                    8800-8803
                                                    8880-8887
                                                    8C00-8C03
                                                    9000-9007

  [ Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20 ]

     :
                                        Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
                                            04.06.2009
                                          9.1.1.1013
                                       Intel
      INF-                                          oem2.inf

     :
      IRQ                                               19
                                                    7400-740F
                                                    7480-748F
                                                    7800-7803
                                                    7880-7887
                                                    7C00-7C03
                                                    8000-8007

  [    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               16
                                                  FE8FFC00-FE8FFFFF
                                                    B400-B40F
                                                    B480-B483
                                                    B800-B807
                                                    B880-B883
                                                    BC00-BC07

  [     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          fdc.inf

     :
      DMA                                               02
      IRQ                                               06
                                                    03F0-03F5
                                                    03F7-03F7

  [ AUWTM4QJ IDE Controller ]

     :
                                        AUWTM4QJ IDE Controller

     :
      IRQ                                               09
                                                    FFE0-FFEF


--------[   ]--------------------------------------------------------------------------------------------

    A:                                                                                                                     
    C:                                               NTFS          51239       48478        2761     5 %  4EB2-801B
    D:                                               NTFS         425697      269163      156534    37 %  EE48-2D11
    G:                                                                                                               


--------[   ]--------------------------------------------------------------------------------------------

  [  #1 - WDC WD5000AAKS-22A7B2 (465 ) ]

    #1 ()    NTFS             C:                                              1 MB    51240 MB
    #2               NTFS             D:                                          51241 MB   425698 MB


--------[   ]---------------------------------------------------------------------------------------

  [ G:\  EDQPEB CX2J4HYRKP2B SCSI CdRom Device ]

      :
                                      EDQPEB CX2J4HYRKP2B SCSI CdRom Device
       firmware                                   1.03
                                             128 
                                              
                               5
                                      4

      :
      BD-ROM                                            
      BD-R                                              
      BD-RE                                             
      HD DVD-ROM                                        
      HD DVD-R                                          
      HD DVD-RW                                         
      DVD-ROM                                           
      DVD+R9 Dual Layer                                 
      DVD+R                                             
      DVD+RW                                            
      DVD-R9 Dual Layer                                 
      DVD-R                                             
      DVD-RW                                            
      DVD-RAM                                            
      CD-ROM                                            
      CD-R                                              
      CD-RW                                             

      :
      Buffer Underrun Protection                         
      C2 Error Pointers                                 
      CD+G                                              
      CD-Text                                           
      Hybrid Disc                                        
      JustLink                                           
      LabelFlash                                         
      Layer-Jump Recording                               
      LightScribe                                        
      Mount Rainier                                      
      SMART                                              
      CSS                                                
      CPRM                                               
      AACS                                               
      VCPS                                               
      BD CPS                                             


--------[ ASPI ]--------------------------------------------------------------------------------------------------------

    00  07  00  -             Port 000                          
    01  07  00  -             Port 001                          
    02  07  00  -             Port 002                          
    03  07  00  -             Port 003                          
    04  07  00  -             Port 004                          
    05  07  00  -             Port 005                          
    06  00  00       EDQPEB    CX2J4HYRKP2B      1.03  
    06  07  00  -             Port 006                          


--------[ ATA ]---------------------------------------------------------------------------------------------------------

  [ WDC WD5000AAKS-22A7B2 (WD-WMASY6344701) ]

      ATA:
      ID                                          WDC WD5000AAKS-22A7B2
                                           WD-WMASY6344701
                                                  01.03B01
      World Wide Name                                   5-0014EE-056636790
                                           SATA-II
                                               : 969021, : 16,   : 63,   : 512
       LBA                                       976773168
                                                   16 
                                           16
       ECC                                         50
                                476940 
       ATA                                      ATA8-ACS

      ATA:
      48-bit LBA                                        
       (APM)                             
      Automatic Acoustic Management                     , 
      Device Configuration Overlay                      
      DMA Setup Auto-Activate                           , 
      General Purpose Logging                           
      Host Protected Area                               , 
      In-Order Data Delivery                             
      Native Command Queuing                            
      Phy Event Counters                                
                                          , 
      Power-Up In Standby                               , 
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      SMART                                             , 
      SMART Error Logging                               
      SMART Self-Test                                   
      Software Settings Preservation                    , 
      Streaming                                          
      Tagged Command Queuing                             
                                               , 

     SSD:
      Data Set Management                                
      Deterministic Read After TRIM                      
       TRIM                                       

     ATA-:
                                                   Western Digital Corporation
                                     http://www.wdc.com/en
                                     http://www.aida64.com/driver-updates


--------[ SMART ]-------------------------------------------------------------------------------------------------------

  [ WDC WD5000AAKS-22A7B2 (WD-WMASY6344701) ]

    01  Raw Read Error Rate                  51   200  200          10  OK:  
    03  Spinup Time                          21   159  158        5050  OK:  
    04  Start/Stop Count                     0    97   97         3916  OK:  
    05  Reallocated Sector Count             140  200  200           0  OK:  
    07  Seek Error Rate                      0    100  253           0  OK:  
    09  Power-On Time Count                  0    83   83        12557  OK:  
    0A  Spinup Retry Count                   0    100  100           0  OK:  
    0B  Calibration Retry Count              0    100  100           0  OK:  
    0C  Power Cycle Count                    0    97   97         3833  OK:  
    C0  Power-Off Retract Count              0    200  200         632  OK:  
    C1  Load/Unload Cycle Count              0    199  199        3916  OK:  
    C2  Temperature                          0    104  89           43  OK:  
    C4  Reallocation Event Count             0    200  200           0  OK:  
    C5  Current Pending Sector Count         0    200  200           1  OK:  
    C6  Offline Uncorrectable Sector Count   0    200  200           1  OK:  
    C7  Ultra ATA CRC Error Rate             0    200  200           0  OK:  
    C8  Write Error Rate                     0    200  200           1  OK:  


--------[  Windows ]------------------------------------------------------------------------------------------------

  [ Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller ]

      :
                                          Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
                                           Gigabit Ethernet
                                         00-22-15-69-A6-E6
                                                 
                                      100 Mbps
      MTU                                               1500 
      DHCP-                               02.11.2011 21:39:31
      DHCP-                               03.11.2011 21:39:31
                                            94724354 (90.3 )
                                          5421239 (5.2 )

      :
       IP /                                 192.168.1.2 / 255.255.255.0
                                                    192.168.1.1
      DHCP                                              192.168.1.1
      DNS                                               192.168.1.1

      :
                                                   Marvell Semiconductor, Inc.
                                     http://www.marvell.com/pc-connectivity
                                       http://www.marvell.com/support
                                     http://www.aida64.com/driver-updates

  [ Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller ]

      :
                                          Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
                                           Gigabit Ethernet
                                         00-22-15-78-FF-72
                                                  2
                                      1000 Mbps
      MTU                                               1500 
                                            0
                                          0

      :
                                                   Marvell Semiconductor, Inc.
                                     http://www.marvell.com/pc-connectivity
                                       http://www.marvell.com/support
                                     http://www.aida64.com/driver-updates

  [ Realtek RTL8139/810x Family Fast Ethernet   ]

      :
                                          Realtek RTL8139/810x Family Fast Ethernet  
                                           Ethernet
                                         00-80-48-2E-2C-3A
                                                  3
                                      10 Mbps
      MTU                                               1500 
                                            0
                                          0

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [ TAP-Win32 Adapter V9 (Tunngle) ]

      :
                                          TAP-Win32 Adapter V9 (Tunngle)
                                           Ethernet
                                         00-FF-37-28-A9-6F
                                              Tunngle
                                      10 Mbps
      MTU                                               1500 
                                            0
                                          0

      :
      DNS                                               7.254.254.254


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    Compex RE100ATX Fast Ethernet Adapter                                             PCI
    Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller                           PCI
    Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller                           PCI


--------[ IAM ]---------------------------------------------------------------------------------------------------------

  [ Microsoft Communities ]

      :
                                        Microsoft Communities
      ID                                   account{3EE63783-9467-428F-8332-FB255D11FBA6}.oeaccount
                                         ( )
                                                (IE  )
      NNTP-                                       msnews.microsoft.com

      :
        NNTP                                
        NNTP                     
        NNTP                        
         NNTP             
       NNTP                
       NNTP   HTML                         

  [ Active Directory ]

      :
                                        Active Directory
      ID                                   account{05E07601-67DA-44FD-A27C-ADB87AA785B9}.oeaccount
                                        LDAP
                                                (IE  )
      LDAP-                                       NULL:3268
        LDAP                             NULL
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     

  [    VeriSign ]

      :
                                           VeriSign
      ID                                   account{7544BEC8-EAB2-4D39-AC5B-B0F61D5A1E0D}.oeaccount
                                        LDAP
                                                (IE  )
      LDAP-                                       directory.verisign.com
      LDAP URL                                          http://www.verisign.com
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        http://www.mail.ru/cnt/8746
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                               

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.1.1  20   192.168.1.2 (Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller)
                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                127.0.0.1  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
              192.168.1.0    255.255.255.0      192.168.1.2  276  192.168.1.2 (Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller)
              192.168.1.2  255.255.255.255      192.168.1.2  276  192.168.1.2 (Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller)
            192.168.1.255  255.255.255.255      192.168.1.2  276  192.168.1.2 (Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller)
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                224.0.0.0        240.0.0.0      192.168.1.2  276  192.168.1.2 (Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller)
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255      192.168.1.2  276  192.168.1.2 (Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller)


--------[ IE Cookie ]---------------------------------------------------------------------------------------------------

    2011-10-29 16:18:01  aparratus@microsoft.com/
    2011-11-01 00:04:23  aparratus@skype.com/
    2011-11-02 21:39:58  aparratus@icq.com/
    2011-11-02 21:39:59  aparratus@mail.ru/


--------[   ]--------------------------------------------------------------------------------------------

    2011-10-30 21:53:09  Aparratus@https://apps.skype.com/friendfinder/?action=search&displayname=expowzik&simple=true&startsearch=true
    2011-10-31 19:41:16  Aparratus@file:///D:/FireFox%20Downloads/RemoveWAT_Windows2.Ru.rar
    2011-10-31 19:41:35  Aparratus@file:///D:/FireFox%20Downloads/Windows2.Ru/Readme.txt
    2011-11-01 00:14:14  Aparratus@https://apps.skype.com/home/index.html
    2011-11-02 22:06:21  Aparratus@file:///D:/FireFox%20Downloads/bluescreenview.zip
    2011-11-02 22:41:38  Aparratus@file:///C:/Users/Aparratus/Desktop/1.txt


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.7600.16385   Final Retail                         70656  14.07.2009 4:14:53
    bdaplgin.ax                               6.01.7600.16385   Final Retail                         74240  14.07.2009 4:14:10
    d3d8.dll                                  6.01.7600.16385   Final Retail                    1036800  14.07.2009 4:15:08
    d3d8thk.dll                               6.01.7600.16385   Final Retail                      11264  14.07.2009 4:15:08
    d3d9.dll                                  6.01.7600.16385   Final Retail                    1826816  14.07.2009 4:15:08
    d3dim.dll                                 6.01.7600.16385   Final Retail                     386048  14.07.2009 4:15:08
    d3dim700.dll                              6.01.7600.16385   Final Retail                     817664  14.07.2009 4:15:08
    d3dramp.dll                               6.01.7600.16385   Final Retail                     593920  14.07.2009 4:15:08
    d3dxof.dll                                6.01.7600.16385   Final Retail                      53760  14.07.2009 4:15:08
    ddraw.dll                                 6.01.7600.16385   Final Retail                        531968  14.07.2009 4:15:10
    ddrawex.dll                               6.01.7600.16385   Final Retail                      30208  14.07.2009 4:15:10
    devenum.dll                               6.06.7600.16385   Final Retail                         66560  14.07.2009 4:15:10
    dinput.dll                                6.01.7600.16385   Final Retail                        136704  14.07.2009 4:15:11
    dinput8.dll                               6.01.7600.16385   Final Retail                        145408  14.07.2009 4:15:11
    dmband.dll                                6.01.7600.16385   Final Retail                      30720  14.07.2009 4:15:12
    dmcompos.dll                              6.01.7600.16385   Final Retail                      63488  14.07.2009 4:15:12
    dmime.dll                                 6.01.7600.16385   Final Retail                     179712  14.07.2009 4:15:12
    dmloader.dll                              6.01.7600.16385   Final Retail                      38400  14.07.2009 4:15:12
    dmscript.dll                              6.01.7600.16385   Final Retail                      86016  14.07.2009 4:15:12
    dmstyle.dll                               6.01.7600.16385   Final Retail                     105984  14.07.2009 4:15:12
    dmsynth.dll                               6.01.7600.16385   Final Retail                     105472  14.07.2009 4:15:12
    dmusic.dll                                6.01.7600.16385   Final Retail                        101376  14.07.2009 4:15:12
    dplaysvr.exe                              6.01.7600.16385   Final Retail                         29184  14.07.2009 4:14:18
    dplayx.dll                                6.01.7600.16385   Final Retail                     213504  14.07.2009 4:15:12
    dpmodemx.dll                              6.01.7600.16385   Final Retail                         23040  14.07.2009 4:15:12
    dpnaddr.dll                               6.01.7600.16385   Final Retail                       2048  14.07.2009 4:04:52
    dpnet.dll                                 6.01.7600.16385   Final Retail                        376832  14.07.2009 4:15:12
    dpnhpast.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnhupnp.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnlobby.dll                              6.01.7600.16385   Final Retail                       2560  14.07.2009 4:04:52
    dpnsvr.exe                                6.01.7600.16385   Final Retail                         33280  14.07.2009 4:14:18
    dpwsockx.dll                              6.01.7600.16385   Final Retail                         44032  14.07.2009 4:15:12
    dsdmo.dll                                 6.01.7600.16385   Final Retail                     173568  14.07.2009 4:15:13
    dsound.dll                                6.01.7600.16385   Final Retail                        453632  14.07.2009 4:15:13
    dswave.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:13
    dxdiagn.dll                               6.01.7600.16385   Final Retail                        210432  14.07.2009 4:15:13
    dxmasf.dll                                12.00.7600.16385  Final Retail                       4096  14.07.2009 4:16:14
    encapi.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:14
    gcdef.dll                                 6.01.7600.16385   Final Retail                        120832  14.07.2009 4:15:22
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  14.07.2009 4:14:10
    ir41_32.ax                                4.51.0016.0003    Final Retail                        839680  14.07.2009 4:14:10
    ir41_qc.dll                               4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir41_qcx.dll                              4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir50_32.dll                               5.2562.0015.0055  Final Retail                        746496  14.07.2009 4:15:34
    ir50_qc.dll                               5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ir50_qcx.dll                              5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  14.07.2009 4:14:10
    joy.cpl                                   6.01.7600.16385   Final Retail                        138240  14.07.2009 4:14:09
    ksproxy.ax                                6.01.7600.16385   Final Retail                        194048  14.07.2009 4:14:11
    kstvtune.ax                               6.01.7600.16385   Final Retail                         84480  14.07.2009 4:14:11
    ksuser.dll                                6.01.7600.16385   Final Retail                          4608  14.07.2009 4:15:35
    kswdmcap.ax                               6.01.7600.16385   Final Retail                        107008  14.07.2009 4:14:11
    ksxbar.ax                                 6.01.7600.16385   Final Retail                         48640  14.07.2009 4:14:11
    mciqtz32.dll                              6.06.7600.16385   Final Retail                         36352  14.07.2009 4:15:37
    mfc40.dll                                 4.01.0000.6151    Beta Retail                         954752  31.08.2010 7:32:30
    mfc42.dll                                 6.06.8064.0000    Beta Retail                        1137664  11.03.2011 8:40:24
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  01.11.2011 4:23:59
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  01.11.2011 4:24:00
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  01.11.2011 4:24:00
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  01.11.2011 4:23:57
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  01.11.2011 4:23:58
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  01.11.2011 4:23:58
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  01.11.2011 4:23:58
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  01.11.2011 4:23:58
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  01.11.2011 4:23:58
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  01.11.2011 4:23:59
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  01.11.2011 4:23:59
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  01.11.2011 4:23:59
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  01.11.2011 4:24:00
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  01.11.2011 4:24:00
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  01.11.2011 4:24:00
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  01.11.2011 4:24:00
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  01.11.2011 4:24:00
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  01.11.2011 4:23:59
    mpeg2data.ax                              6.06.7600.16385   Final Retail                         72704  14.07.2009 4:14:11
    mpg2splt.ax                               6.06.7600.16724   Final Retail                     199680  23.12.2010 8:24:02
    msdmo.dll                                 6.06.7600.16385   Final Retail                      30208  14.07.2009 4:15:43
    msdvbnp.ax                                6.06.7600.16385   Final Retail                         59904  14.07.2009 4:14:11
    msvidctl.dll                              6.05.7600.16385   Final Retail                       2291712  14.07.2009 4:15:50
    msyuv.dll                                 6.01.7600.16490   Final Retail                      22016  19.12.2009 12:02:46
    pid.dll                                   6.01.7600.16385   Final Retail                      36352  14.07.2009 4:16:12
    psisdecd.dll                              6.06.7600.16485   Final Retail                        465408  13.12.2009 12:30:50
    psisrndr.ax                               6.06.7600.16385   Final Retail                         75776  14.07.2009 4:14:11
    qasf.dll                                  12.00.7600.16385  Final Retail                     206848  14.07.2009 4:16:12
    qcap.dll                                  6.06.7600.16385   Final Retail                        190976  14.07.2009 4:16:12
    qdv.dll                                   6.06.7600.16385   Final Retail                        283136  14.07.2009 4:16:12
    qdvd.dll                                  6.06.7600.16385   Final Retail                        514560  14.07.2009 4:16:12
    qedit.dll                                 6.06.7600.16385   Final Retail                        509440  14.07.2009 4:16:12
    qedwipes.dll                              6.06.7600.16385   Final Retail                     733184  14.07.2009 4:09:35
    quartz.dll                                6.06.7600.16490   Final Retail                       1328640  19.12.2009 12:02:48
    vbisurf.ax                                6.01.7600.16385   Final Retail                      33280  14.07.2009 4:14:11
    vfwwdm32.dll                              6.01.7600.16385   Final Retail                         56832  14.07.2009 4:16:17
    wsock32.dll                               6.01.7600.16385   Final Retail                         15360  14.07.2009 4:16:20


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       nvd3dum.dll (8.17.12.8562 - nVIDIA ForceWare 285.62)
                                      NVIDIA GeForce GTX 580

     Direct3D:
      /                         1536  / 1433 
                                8, 16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x, CSAA 8x, CSAA 8xQ, CSAA 16x, CSAA 16xQ
                               1 x 1
                              8192 x 8192
                              5.0
        DirectX                      DirectX v11.0

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Compute Shader                                    
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      DirectX Texture Compression                        
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Double-Precision Floating-Point                   
      Driver Concurrent Creates                         
      Driver Command Lists                              
      Dynamic Textures                                  
      Edge Anti-Aliasing                                
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Geometry Shader                                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                    
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      3x11                                              
      3x16                                              
      AI44                                              
      AIP8                                              
      ATOC                                              
      AV12                                              
      AYUV                                              
      NV12                                              
      NV24                                              
      NVDB                                              
      NVDP                                              
      NVMD                                              
      PLFF                                              
      SSAA                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (SoundMAX Integrated Digital HD Audio) ]

     DirectSound:
                                       (SoundMAX Integrated Digital HD Audio)
                                          {0.0.0.00000000}.{f003fc05-ff58-48c9-8f10-8c1aedb55ee1}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  SPDIF (SoundMAX Integrated Digital HD Audio) ]

     DirectSound:
                                       SPDIF (SoundMAX Integrated Digital HD Audio)
                                          {0.0.0.00000000}.{25b934bd-089d-4890-a872-f1a38b3117f0}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (Avnex Virtual Audio Device) ]

     DirectSound:
                                       (Avnex Virtual Audio Device)
                                          {0.0.0.00000000}.{655372b2-fc61-4494-b4bc-370366ba668c}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [   (SoundMAX Integrated Digital HD Audio) ]

     DirectSound:
                                        (SoundMAX Integrated Digital HD Audio)
                                          {0.0.0.00000000}.{f82e1219-b13a-4b8f-8bf2-c3970bc52e88}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [  ]

     DirectInput:
                                      
                                           
                                        
                                                     3
      /                                    8

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [  ]

     DirectInput:
                                      
                                           
                                        
      /                                    128

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ Razer Gaming Device ]

     DirectInput:
                                      Razer Gaming Device
                                           
                                        
      /                                    573

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      


--------[  Windows ]------------------------------------------------------------------------------------------

  [  ]

    DVD  CD-ROM :
      EDQPEB CX2J4HYRKP2B SCSI CdRom Device             6.1.7600.16385

    IDE ATA/ATAPI :
      ATA Channel 0                                     6.1.7600.16385
      ATA Channel 0                                     6.1.7600.16385
      ATA Channel 0                                     6.1.7600.16385
      ATA Channel 1                                     6.1.7600.16385
      ATA Channel 1                                     6.1.7600.16385
      ATA Channel 1                                     6.1.7600.16385
      Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A269.1.1.1013
      Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A209.1.1.1013
         PCI IDE      6.1.7600.16385

    Razer Device:
      Razer Gaming Device                               1.0.0.1

    :
      NVIDIA GeForce GTX 580                            8.17.12.8562

      :
                                                6.1.7600.16385

     :
      WDC WD5000AAKS-22A7B2 ATA Device                  6.1.7600.16385

      :
      Ancillary Function Driver for Winsock             
      AsIO                                              
      AsUpIO                                            
      Beep                                              
      CNG                                               
      ehdrv                                             
      epfwwfpr                                          
      Hardware Policy Driver                            
      HTTP                                              
      Kernel Mode Driver Frameworks service             
      KSecDD                                            
      KSecPkg                                           
      LDDM Graphics Subsystem                           
      Link-Layer Topology Discovery Mapper I/O Driver   
      Link-Layer Topology Discovery Responder           
      msisadrv                                          
      NativeWiFi Filter                                 
      NDIS Usermode I/O Protocol                        
      NDProxy                                           
      NETBT                                             
      NSI proxy service driver.                         
      Null                                              
      PEAUTH                                            
      Performance Counters for Windows Driver           
      RDP Encoder Mirror Driver                         
      RDPCDD                                            
      Reflector Display Driver used to gain access to graphics data
      Security Driver                                   
      Security Processor Loader Driver                  
      sptd                                              
      System Attribute Cache                            
      TCP/IP Registry Compatibility                     
      User Mode Driver Frameworks Platform Driver       
      VgaSave                                           
      WFP Lightweight Filter                            
            
                              
                               
                                 
         Windows           
        NetIO Legacy TDI                
        TCP/IP                          
         IPv6 ARP               
          Bitlocker        
        (CLFS)                               
        QoS                           
        NDIS                            
                               

    ,    :
      Avnex Virtual Audio Device                        1.0.0.1
      NVIDIA High Definition Audio                      1.2.24.0
      NVIDIA High Definition Audio                      1.2.24.0
      NVIDIA High Definition Audio                      1.2.24.0
      NVIDIA High Definition Audio                      1.2.24.0
      SoundMAX Integrated Digital HD Audio              6.10.2.6600

    :
       HID                                    6.1.7600.16385
        PS/2                       6.1.7600.16385

    :
      ACPI x64-based PC                                 6.1.7600.16385

     USB:
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       - USB   Intel(R) ICH10 - 3A3A6.1.7600.16385
       - USB   Intel(R) ICH10 - 3A3C6.1.7600.16385
       - USB   Intel(R) ICH10 - 3A346.1.7600.16385
       - USB   Intel(R) ICH10 - 3A356.1.7600.16385
       - USB   Intel(R) ICH10 - 3A366.1.7600.16385
       - USB   Intel(R) ICH10 - 3A376.1.7600.16385
       - USB   Intel(R) ICH10 - 3A386.1.7600.16385
       - USB   Intel(R) ICH10 - 3A396.1.7600.16385

      :
                       6.1.7600.16385

      :
      AUWTM4QJ IDE Controller                           

    :
        PnP                         6.1.7600.16385

        :
      HID-                               6.1.7600.16385
      HID-                               6.1.7600.16385

    :
      Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz   6.1.7600.16385
      Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz   6.1.7600.16385
      Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz   6.1.7600.16385
      Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz   6.1.7600.16385

     :
      Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller #211.10.5.3
      Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller11.10.5.3
      Realtek RTL8139/810x Family Fast Ethernet  6.111.530.2008
      TAP-Win32 Adapter V9 (Tunngle)                    9.0.0.6
      Teredo Tunneling Pseudo-Interface                 6.1.7600.16385
      WAN Miniport (IKEv2)                              6.1.7600.16385
       Microsoft 6to4 #2                         6.1.7600.16385
       Microsoft 6to4                            6.1.7600.16385
       Microsoft ISATAP #2                       6.1.7600.16385
       Microsoft ISATAP #3                       6.1.7600.16385
       Microsoft ISATAP #4                       6.1.7600.16385
       Microsoft ISATAP                          6.1.7600.16385
       WAN (IP)                                 6.1.7600.16385
       WAN (IPv6)                               6.1.7600.16385
       WAN (L2TP)                               6.1.7600.16385
       WAN (PPPoE)                              6.1.7600.16385
       WAN (PPTP)                               6.1.7600.16385
      - WAN (SSTP)                              6.1.7600.16385
       WAN ( )                    6.1.7600.16385

     :
      ATK0110 ACPI UTILITY                              1043.6.0.0
      CMOS                                         6.1.7600.16385
      Intel(R) 82801 PCI  - 244E                    6.1.7600.16385
      Intel(R) 82802 Firmware               6.1.7600.16385
      Intel(R) ICH10 Family SMBus Controller - 3A30     1.0.0.2
      Microsoft ACPI-                 6.1.7600.16385
      Microsoft System Management BIOS           6.1.7600.16385
      Remote Desktop Device Redirector Bus              6.1.7600.16385
      UMBus                    6.1.7600.16385
      UMBus                                6.1.7600.16385
                               6.1.7600.16385
                                       6.1.7600.16385
                               6.1.7600.16385
                                          6.1.7600.16385
                      6.1.7600.16385
                            6.1.7600.16385
          ()6.1.7600.16385
                               6.1.7600.16385
        ACPI                               6.1.7600.16385
       High Definition Audio (Microsoft)      6.1.7600.16385
       High Definition Audio (Microsoft)      6.1.7600.16385
       Intel(R) 4 Series Chipset Processor to I/O - 2E206.1.7600.16385
       LPC- Intel(R) ICH10R - 3A16  6.1.7600.16385
                         6.1.7600.16385
        Intel(R) 4 Series Chipset PCI Express - 2E216.1.7600.16385
        PCI Express 1  Intel(R) ICH10 - 3A406.1.7600.16385
        PCI Express 3  Intel(R) ICH10 - 3A446.1.7600.16385
        PCI Express 4  Intel(R) ICH10 - 3A466.1.7600.16385
        PCI Express 5  Intel(R) ICH10 - 3A486.1.7600.16385
                            6.1.7600.16385
         Plug and Play 6.1.7600.16385
                     6.1.7600.16385
        /                     6.1.7600.16385
                                   6.1.7600.16385
                                   6.1.7600.16385
                                   6.1.7600.16385
                                   6.1.7600.16385
                                   6.1.7600.16385
                                          6.1.7600.16385
                                          6.1.7600.16385
                                         6.1.7600.16385
         ACPI          6.1.7600.16385
       PCI                                          6.1.7600.16385

      :
                                        6.1.7600.16385
                                        6.1.7600.16385

     HID (Human Interface Devices):
      DeathAdder Mouse                                  1.0.5.0
      HID-               6.1.7600.16385

    -  IEEE 1394:
      VIA 1394 OHCI- -         6.1.7600.16385

  [ DVD  CD-ROM  / EDQPEB CX2J4HYRKP2B SCSI CdRom Device ]

     :
                                        EDQPEB CX2J4HYRKP2B SCSI CdRom Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cdrom.inf
       ID                                     SCSI\CdRomEDQPEB__CX2J4HYRKP2B____1.03
                                     Bus Number 0, Target ID 0, LUN 0

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     Intel-3a26
                                     Channel 0

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     Intel-3a20
                                     Channel 0

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     11ab-6121
                                     Channel 0

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     Intel-3a26
                                     Channel 1

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     Intel-3a20
                                     Channel 1

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     11ab-6121
                                     Channel 1

  [ IDE ATA/ATAPI  / Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26 ]

     :
                                        Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
                                            04.06.2009
                                          9.1.1.1013
                                       Intel
      INF-                                          oem2.inf
       ID                                     PCI\VEN_8086&DEV_3A26&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,31,5)
      PCI-                                    Intel 82801JB ICH10 - 2-port SATA Controller

     :
      IRQ                                               19
                                                    8400-840F
                                                    8480-848F
                                                    8800-8803
                                                    8880-8887
                                                    8C00-8C03
                                                    9000-9007

  [ IDE ATA/ATAPI  / Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20 ]

     :
                                        Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
                                            04.06.2009
                                          9.1.1.1013
                                       Intel
      INF-                                          oem2.inf
       ID                                     PCI\VEN_8086&DEV_3A20&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,31,2)
      PCI-                                    Intel 82801JB ICH10 - 4-port SATA Controller

     :
      IRQ                                               19
                                                    7400-740F
                                                    7480-748F
                                                    7800-7803
                                                    7880-7887
                                                    7C00-7C03
                                                    8000-8007

  [ IDE ATA/ATAPI  /    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     PCI\VEN_11AB&DEV_6121&SUBSYS_612111AB&REV_B1
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(2,0,0)
      PCI-                                    Marvell 88SE6121 Serial ATA II Host Controller

     :
      IRQ                                               16
                                                  FE8FFC00-FE8FFFFF
                                                    B400-B40F
                                                    B480-B483
                                                    B800-B807
                                                    B880-B883
                                                    BC00-BC07

  [ Razer Device / Razer Gaming Device ]

     :
                                        Razer Gaming Device
                                            04.11.2009
                                          1.0.0.1
                                       Razer
      INF-                                          oem11.inf
       ID                                     {ECDCA5B4-E50C-40bc-B492-C4DB850B7812}\HID_DEVICE

  [  / NVIDIA GeForce GTX 580 ]

     :
                                        NVIDIA GeForce GTX 580
                                            15.10.2011
                                          8.17.12.8562
                                       NVIDIA
      INF-                                          oem6.inf
       ID                                     PCI\VEN_10DE&DEV_1080&SUBSYS_120319DA&REV_A1
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(1,0,0)
      PCI-                                    Zotac GeForce GTX 580 Video Adapter

     :
      IRQ                                               16
                                                  000A0000-000BFFFF
                                                  F0000000-F7FFFFFF
                                                  F8000000-F9FFFFFF
                                                  FD000000-FDFFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    AC00-AC7F

     :
                                                   ZOTAC International (MCO) Limited
                                     http://www.zotac.com/index.php?option=com_wrapper&Itemid=483
                                       http://www.zotac.com/index.php?option=com_docman&task=cat_view&gid=44&Itemid=218
                                     http://www.aida64.com/driver-updates

  [    /  ]

     :
                                        
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          flpydisk.inf
       ID                                     FDC\GENERIC_FLOPPY_DRIVE

  [   / WDC WD5000AAKS-22A7B2 ATA Device ]

     :
                                        WDC WD5000AAKS-22A7B2 ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     IDE\DiskWDC_WD5000AAKS-22A7B2___________________01.03B01
                                     Channel 0, Target 0, Lun 0

     :
                                                   Western Digital Corporation
                                     http://www.wdc.com/en
                                     http://www.aida64.com/driver-updates

  [    / Ancillary Function Driver for Winsock ]

     :
                                        Ancillary Function Driver for Winsock

  [    / AsIO ]

     :
                                        AsIO

  [    / AsUpIO ]

     :
                                        AsUpIO

  [    / Beep ]

     :
                                        Beep

  [    / CNG ]

     :
                                        CNG

  [    / ehdrv ]

     :
                                        ehdrv

  [    / epfwwfpr ]

     :
                                        epfwwfpr

  [    / Hardware Policy Driver ]

     :
                                        Hardware Policy Driver

  [    / HTTP ]

     :
                                        HTTP

  [    / Kernel Mode Driver Frameworks service ]

     :
                                        Kernel Mode Driver Frameworks service

  [    / KSecDD ]

     :
                                        KSecDD

  [    / KSecPkg ]

     :
                                        KSecPkg

  [    / LDDM Graphics Subsystem ]

     :
                                        LDDM Graphics Subsystem

  [    / Link-Layer Topology Discovery Mapper I/O Driver ]

     :
                                        Link-Layer Topology Discovery Mapper I/O Driver

  [    / Link-Layer Topology Discovery Responder ]

     :
                                        Link-Layer Topology Discovery Responder

  [    / msisadrv ]

     :
                                        msisadrv

  [    / NativeWiFi Filter ]

     :
                                        NativeWiFi Filter

  [    / NDIS Usermode I/O Protocol ]

     :
                                        NDIS Usermode I/O Protocol

  [    / NDProxy ]

     :
                                        NDProxy

  [    / NETBT ]

     :
                                        NETBT

  [    / NSI proxy service driver. ]

     :
                                        NSI proxy service driver.

  [    / Null ]

     :
                                        Null

  [    / PEAUTH ]

     :
                                        PEAUTH

  [    / Performance Counters for Windows Driver ]

     :
                                        Performance Counters for Windows Driver

  [    / RDP Encoder Mirror Driver ]

     :
                                        RDP Encoder Mirror Driver

  [    / RDPCDD ]

     :
                                        RDPCDD

  [    / Reflector Display Driver used to gain access to graphics data ]

     :
                                        Reflector Display Driver used to gain access to graphics data

  [    / Security Driver ]

     :
                                        Security Driver

  [    / Security Processor Loader Driver ]

     :
                                        Security Processor Loader Driver

  [    / sptd ]

     :
                                        sptd

  [    / System Attribute Cache ]

     :
                                        System Attribute Cache

  [    / TCP/IP Registry Compatibility ]

     :
                                        TCP/IP Registry Compatibility

  [    / User Mode Driver Frameworks Platform Driver ]

     :
                                        User Mode Driver Frameworks Platform Driver

  [    / VgaSave ]

     :
                                        VgaSave

  [    / WFP Lightweight Filter ]

     :
                                        WFP Lightweight Filter

  [    /        ]

     :
                                              

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /    Windows ]

     :
                                           Windows

  [    /   NetIO Legacy TDI ]

     :
                                          NetIO Legacy TDI

  [    /   TCP/IP ]

     :
                                          TCP/IP

  [    /    IPv6 ARP ]

     :
                                           IPv6 ARP

  [    /     Bitlocker ]

     :
                                            Bitlocker

  [    /   (CLFS) ]

     :
                                          (CLFS)

  [    /   QoS ]

     :
                                          QoS

  [    /   NDIS ]

     :
                                          NDIS

  [    /    ]

     :
                                          

  [ ,     / Avnex Virtual Audio Device ]

     :
                                        Avnex Virtual Audio Device
                                            04.02.2009
                                          1.0.0.1
                                       AVNEX Ltd.
      INF-                                          oem14.inf

  [ ,     / NVIDIA High Definition Audio ]

     :
                                        NVIDIA High Definition Audio
                                            07.07.2011
                                          1.2.24.0
                                       NVIDIA Corporation
      INF-                                          oem26.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001
                                       High Definition Audio

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / NVIDIA High Definition Audio ]

     :
                                        NVIDIA High Definition Audio
                                            07.07.2011
                                          1.2.24.0
                                       NVIDIA Corporation
      INF-                                          oem26.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001
                                       High Definition Audio

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / NVIDIA High Definition Audio ]

     :
                                        NVIDIA High Definition Audio
                                            07.07.2011
                                          1.2.24.0
                                       NVIDIA Corporation
      INF-                                          oem26.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001
                                       High Definition Audio

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / NVIDIA High Definition Audio ]

     :
                                        NVIDIA High Definition Audio
                                            07.07.2011
                                          1.2.24.0
                                       NVIDIA Corporation
      INF-                                          oem26.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0018&SUBSYS_10DE0101&REV_1001
                                       High Definition Audio

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / SoundMAX Integrated Digital HD Audio ]

     :
                                        SoundMAX Integrated Digital HD Audio
                                            17.09.2009
                                          6.10.2.6600
                                       AnalogDevices
      INF-                                          oem5.inf
       ID                                     HDAUDIO\FUNC_01&VEN_11D4&DEV_989B&SUBSYS_10438334&REV_1003
                                       High Definition Audio

     :
                                                   Analog Devices, Inc.
                                     http://www.analog.com
                                       http://www.analog.com
                                     http://www.aida64.com/driver-updates

  [  /  HID ]

     :
                                         HID
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          keyboard.inf
       ID                                     HID\GSPYVHid&Col03

  [  /   PS/2 ]

     :
                                          PS/2
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          keyboard.inf
       ID                                     ACPI\PNP0303
      PnP-                                    101/102-Key or MS Natural Keyboard

     :
      IRQ                                               01
                                                    0060-0060
                                                    0064-0064

  [  / ACPI x64-based PC ]

     :
                                        ACPI x64-based PC
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hal.inf
       ID                                     acpiapic

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID8086&PID3A36&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID8086&PID3A39&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID8086&PID3A35&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID8086&PID3A38&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID8086&PID3A34&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID8086&PID3A37&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID8086&PID3A3A&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID8086&PID3A3C&REV0000

  [  USB /  - USB   Intel(R) ICH10 - 3A3A ]

     :
                                         - USB   Intel(R) ICH10 - 3A3A
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_8086&DEV_3A3A&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,29,7)
      PCI-                                    Intel 82801JB ICH10 - USB2 Enhanced Host Controller

     :
      IRQ                                               23
                                                  FCFFF800-FCFFFBFF

  [  USB /  - USB   Intel(R) ICH10 - 3A3C ]

     :
                                         - USB   Intel(R) ICH10 - 3A3C
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_8086&DEV_3A3C&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,26,7)
      PCI-                                    Intel 82801JB ICH10 - USB2 Enhanced Host Controller

     :
      IRQ                                               18
                                                  FCFFFC00-FCFFFFFF

  [  USB /  - USB   Intel(R) ICH10 - 3A34 ]

     :
                                         - USB   Intel(R) ICH10 - 3A34
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_8086&DEV_3A34&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,29,0)
      PCI-                                    Intel 82801JB ICH10 - USB Universal Host Controller

     :
      IRQ                                               23
                                                    9080-909F

  [  USB /  - USB   Intel(R) ICH10 - 3A35 ]

     :
                                         - USB   Intel(R) ICH10 - 3A35
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_8086&DEV_3A35&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,29,1)
      PCI-                                    Intel 82801JB ICH10 - USB Universal Host Controller

     :
      IRQ                                               19
                                                    9400-941F

  [  USB /  - USB   Intel(R) ICH10 - 3A36 ]

     :
                                         - USB   Intel(R) ICH10 - 3A36
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_8086&DEV_3A36&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,29,2)
      PCI-                                    Intel 82801JB ICH10 - USB Universal Host Controller

     :
      IRQ                                               18
                                                    9480-949F

  [  USB /  - USB   Intel(R) ICH10 - 3A37 ]

     :
                                         - USB   Intel(R) ICH10 - 3A37
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_8086&DEV_3A37&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,26,0)
      PCI-                                    Intel 82801JB ICH10 - USB Universal Host Controller

     :
      IRQ                                               16
                                                    9800-981F

  [  USB /  - USB   Intel(R) ICH10 - 3A38 ]

     :
                                         - USB   Intel(R) ICH10 - 3A38
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_8086&DEV_3A38&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,26,1)
      PCI-                                    Intel 82801JB ICH10 - USB Universal Host Controller

     :
      IRQ                                               21
                                                    9880-989F

  [  USB /  - USB   Intel(R) ICH10 - 3A39 ]

     :
                                         - USB   Intel(R) ICH10 - 3A39
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_8086&DEV_3A39&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,26,2)
      PCI-                                    Intel 82801JB ICH10 - USB Universal Host Controller

     :
      IRQ                                               18
                                                    9C00-9C1F

  [    /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          fdc.inf
       ID                                     ACPI\PNP0700
      PnP-                                    Floppy Disk Controller

     :
      DMA                                               02
      IRQ                                               06
                                                    03F0-03F5
                                                    03F7-03F7

  [    / AUWTM4QJ IDE Controller ]

     :
                                        AUWTM4QJ IDE Controller
       ID                                     ACPI\PNPA000
      PnP-                                    Adaptec 154x-compatible Controller

     :
      IRQ                                               09
                                                    FFE0-FFEF

  [  /   PnP ]

     :
                                          PnP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          monitor.inf
       ID                                     MONITOR\VSC6B20
                                                 ViewSonic VX2240w

     :
                                                   ViewSonic Corporation
                                     http://www.viewsonic.com/products
                                       http://www.viewsonic.com/support/downloads/drivers
                                     http://www.aida64.com/driver-updates

  [      / HID-  ]

     :
                                        HID- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msmouse.inf
       ID                                     HID\VID_1532&PID_0016&REV_0100

  [      / HID-  ]

     :
                                        HID- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msmouse.inf
       ID                                     HID\GSPYVHid&Col02

  [  / Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz ]

     :
                                        Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\GenuineIntel_-_Intel64_Family_6_Model_23

  [  / Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz ]

     :
                                        Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\GenuineIntel_-_Intel64_Family_6_Model_23

  [  / Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz ]

     :
                                        Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\GenuineIntel_-_Intel64_Family_6_Model_23

  [  / Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz ]

     :
                                        Intel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\GenuineIntel_-_Intel64_Family_6_Model_23

  [   / Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller #2 ]

     :
                                        Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller #2
                                            20.05.2009
                                          11.10.5.3
                                       Marvell
      INF-                                          oem4.inf
       ID                                     PCI\VEN_11AB&DEV_4364&SUBSYS_81F81043&REV_12
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(3,0,0)
      PCI-                                    Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller

     :
      IRQ                                               19
                                                  FE9FC000-FE9FFFFF
                                                    C800-C8FF

      :
                                                   Marvell Semiconductor, Inc.
                                     http://www.marvell.com/pc-connectivity
                                       http://www.marvell.com/support
                                     http://www.aida64.com/driver-updates

  [   / Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller ]

     :
                                        Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
                                            20.05.2009
                                          11.10.5.3
                                       Marvell
      INF-                                          oem4.inf
       ID                                     PCI\VEN_11AB&DEV_4364&SUBSYS_81F81043&REV_12
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(4,0,0)
      PCI-                                    Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller

     :
      IRQ                                               18
                                                  FEAFC000-FEAFFFFF
                                                    D800-D8FF

      :
                                                   Marvell Semiconductor, Inc.
                                     http://www.marvell.com/pc-connectivity
                                       http://www.marvell.com/support
                                     http://www.aida64.com/driver-updates

  [   / Realtek RTL8139/810x Family Fast Ethernet   ]

     :
                                        Realtek RTL8139/810x Family Fast Ethernet  
                                            30.05.2008
                                          6.111.530.2008
                                       Microsoft
      INF-                                          netrtl64.inf
       ID                                     PCI\VEN_10EC&DEV_8139&SUBSYS_813911F6&REV_10
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(6,0,0)
      PCI-                                    Compex RE100ATX Fast Ethernet Adapter

     :
      IRQ                                               16
                                                  FEBFFC00-FEBFFCFF
                                                    E800-E8FF

      :
                                                   Compex Corporation
                                     http://www.compex.com/ps.htm
                                       http://www.compex.com/ps.htm
                                     http://www.aida64.com/driver-updates

  [   / TAP-Win32 Adapter V9 (Tunngle) ]

     :
                                        TAP-Win32 Adapter V9 (Tunngle)
                                            16.09.2009
                                          9.0.0.6
                                       TAP-Win32 Provider V9 (Tunngle)
      INF-                                          oem24.inf
       ID                                     TAP0901T

  [   / Teredo Tunneling Pseudo-Interface ]

     :
                                        Teredo Tunneling Pseudo-Interface
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *TEREDO

  [   / WAN Miniport (IKEv2) ]

     :
                                        WAN Miniport (IKEv2)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netavpna.inf
       ID                                     ms_agilevpnminiport

  [   /  Microsoft 6to4 #2 ]

     :
                                         Microsoft 6to4 #2
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *6to4mp

  [   /  Microsoft 6to4 ]

     :
                                         Microsoft 6to4
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *6to4mp

  [   /  Microsoft ISATAP #2 ]

     :
                                         Microsoft ISATAP #2
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  Microsoft ISATAP #3 ]

     :
                                         Microsoft ISATAP #3
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  Microsoft ISATAP #4 ]

     :
                                         Microsoft ISATAP #4
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  Microsoft ISATAP ]

     :
                                         Microsoft ISATAP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  WAN (IP) ]

     :
                                        WAN Miniport (IP)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanip

  [   /  WAN (IPv6) ]

     :
                                        WAN Miniport (IPv6)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanipv6

  [   /  WAN (L2TP) ]

     :
                                        WAN Miniport (L2TP)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_l2tpminiport

  [   /  WAN (PPPoE) ]

     :
                                        WAN Miniport (PPPOE)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_pppoeminiport

  [   /  WAN (PPTP) ]

     :
                                        WAN Miniport (PPTP)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_pptpminiport

  [   / - WAN (SSTP) ]

     :
                                        WAN Miniport (SSTP)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netsstpa.inf
       ID                                     ms_sstpminiport

  [   /  WAN ( ) ]

     :
                                        WAN Miniport (Network Monitor)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanbh

  [   / ATK0110 ACPI UTILITY ]

     :
                                        ATK0110 ACPI UTILITY
                                            16.07.2009
                                          1043.6.0.0
                                       ATK
      INF-                                          oem1.inf
       ID                                     ACPI\ATK0110
      PnP-                                    Asus ATK-110 ACPI Utility

  [   / CMOS   ]

     :
                                        CMOS  
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0B00
      PnP-                                    Real-Time Clock

     :
      IRQ                                               08
                                                    0070-0071

  [   / Intel(R) 82801 PCI  - 244E ]

     :
                                        Intel(R) 82801 PCI  - 244E
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_8086&DEV_244E&SUBSYS_82D41043&REV_90
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,30,0)
      PCI-                                    Intel 82801JB I/O Controller Hub 10 (ICH10) [A-0]

     :
                                                  FEB00000-FEBFFFFF
                                                    E000-EFFF

  [   / Intel(R) 82802 Firmware  ]

     :
                                        Intel(R) 82802 Firmware 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\INT0800
      PnP-                                    Intel Flash EEPROM

     :
                                                  FFA00000-FFBFFFFF
                                                  FFE00000-FFFFFFFF

  [   / Intel(R) ICH10 Family SMBus Controller - 3A30 ]

     :
                                        Intel(R) ICH10 Family SMBus Controller - 3A30
                                            04.06.2009
                                          1.0.0.2
                                       Intel
      INF-                                          oem3.inf
       ID                                     PCI\VEN_8086&DEV_3A30&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,31,3)
      PCI-                                    Intel 82801JB ICH10 - SMBus Controller

     :
      IRQ                                               15
                                                  FCFFF400-FCFFF4FF
                                                    0400-041F

  [   / Microsoft ACPI-  ]

     :
                                        Microsoft ACPI- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          acpi.inf
       ID                                     ACPI_HAL\PNP0C08
      PnP-                                    ACPI Driver/BIOS

     :
      IRQ                                               100
      IRQ                                               101
      IRQ                                               102
      IRQ                                               103
      IRQ                                               104
      IRQ                                               105
      IRQ                                               106
      IRQ                                               107
      IRQ                                               108
      IRQ                                               109
      IRQ                                               110
      IRQ                                               111
      IRQ                                               112
      IRQ                                               113
      IRQ                                               114
      IRQ                                               115
      IRQ                                               116
      IRQ                                               117
      IRQ                                               118
      IRQ                                               119
      IRQ                                               120
      IRQ                                               121
      IRQ                                               122
      IRQ                                               123
      IRQ                                               124
      IRQ                                               125
      IRQ                                               126
      IRQ                                               127
      IRQ                                               128
      IRQ                                               129
      IRQ                                               130
      IRQ                                               131
      IRQ                                               132
      IRQ                                               133
      IRQ                                               134
      IRQ                                               135
      IRQ                                               136
      IRQ                                               137
      IRQ                                               138
      IRQ                                               139
      IRQ                                               140
      IRQ                                               141
      IRQ                                               142
      IRQ                                               143
      IRQ                                               144
      IRQ                                               145
      IRQ                                               146
      IRQ                                               147
      IRQ                                               148
      IRQ                                               149
      IRQ                                               150
      IRQ                                               151
      IRQ                                               152
      IRQ                                               153
      IRQ                                               154
      IRQ                                               155
      IRQ                                               156
      IRQ                                               157
      IRQ                                               158
      IRQ                                               159
      IRQ                                               160
      IRQ                                               161
      IRQ                                               162
      IRQ                                               163
      IRQ                                               164
      IRQ                                               165
      IRQ                                               166
      IRQ                                               167
      IRQ                                               168
      IRQ                                               169
      IRQ                                               170
      IRQ                                               171
      IRQ                                               172
      IRQ                                               173
      IRQ                                               174
      IRQ                                               175
      IRQ                                               176
      IRQ                                               177
      IRQ                                               178
      IRQ                                               179
      IRQ                                               180
      IRQ                                               181
      IRQ                                               182
      IRQ                                               183
      IRQ                                               184
      IRQ                                               185
      IRQ                                               186
      IRQ                                               187
      IRQ                                               188
      IRQ                                               189
      IRQ                                               190
      IRQ                                               81
      IRQ                                               82
      IRQ                                               83
      IRQ                                               84
      IRQ                                               85
      IRQ                                               86
      IRQ                                               87
      IRQ                                               88
      IRQ                                               89
      IRQ                                               90
      IRQ                                               91
      IRQ                                               92
      IRQ                                               93
      IRQ                                               94
      IRQ                                               95
      IRQ                                               96
      IRQ                                               97
      IRQ                                               98
      IRQ                                               99

  [   / Microsoft System Management BIOS  ]

     :
                                        Microsoft System Management BIOS 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\mssmbios

  [   / Remote Desktop Device Redirector Bus ]

     :
                                        Remote Desktop Device Redirector Bus
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          rdpbus.inf
       ID                                     ROOT\RDPBUS

  [   / UMBus    ]

     :
                                        UMBus   
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     root\umbus

  [   / UMBus  ]

     :
                                        UMBus 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     UMB\UMBUS

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C04
      PnP-                                    Numeric Data Processor

     :
      IRQ                                               13
                                                    00F0-00FF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0800
      PnP-                                    PC Speaker

     :
                                                    0061-0061

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0103
      PnP-                                    High Precision Event Timer

     :
                                                  FED00000-FED003FF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\VOLMGR

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\RDP_KBD

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\RDP_MOU

  [   /     () ]

     :
                                            ()
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\vdrvroot

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          blbdrive.inf
       ID                                     ROOT\BLBDRIVE

  [   /   ACPI ]

     :
                                          ACPI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C0C
      PnP-                                    Power Button

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            13.07.2009
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hdaudbus.inf
       ID                                     PCI\VEN_8086&DEV_3A3E&SUBSYS_83341043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,27,0)
      PCI-                                    Intel 82801JB ICH10 - High Definition Audio Controller

     :
      IRQ                                               22
                                                  FCFF8000-FCFFBFFF

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            13.07.2009
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hdaudbus.inf
       ID                                     PCI\VEN_10DE&DEV_0E09&SUBSYS_120319DA&REV_A1
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(1,0,1)
      PCI-                                    nVIDIA GF110 - High Definition Audio Controller

     :
      IRQ                                               17
                                                  FE7FC000-FE7FFFFF

  [   /  Intel(R) 4 Series Chipset Processor to I/O - 2E20 ]

     :
                                         Intel(R) 4 Series Chipset Processor to I/O - 2E20
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_8086&DEV_2E20&SUBSYS_82D31043&REV_02
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,0,0)
      PCI-                                    Intel G43/G45/P43/P45 Chipset - Memory Controller Hub [A-2]

  [   /  LPC- Intel(R) ICH10R - 3A16 ]

     :
                                         LPC- Intel(R) ICH10R - 3A16
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_8086&DEV_3A16&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,31,0)
      PCI-                                    Intel 82801JB ICH10R - LPC Bridge

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0200
      PnP-                                    DMA Controller

     :
      DMA                                               04
                                                    0000-000F
                                                    0081-0083
                                                    0087-0087
                                                    0089-008B
                                                    008F-008F
                                                    00C0-00DF

  [   /   Intel(R) 4 Series Chipset PCI Express - 2E21 ]

     :
                                          Intel(R) 4 Series Chipset PCI Express - 2E21
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_8086&DEV_2E21&SUBSYS_82D31043&REV_02
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,1,0)
      PCI-                                    Intel G43/G45/P43/P45 Chipset - Primary PCI Express x16 Root [A-2]

     :
      IRQ                                               16
                                                  000A0000-000BFFFF
                                                  F0000000-F9FFFFFF
                                                  FD000000-FE7FFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    A000-AFFF

  [   /   PCI Express 1  Intel(R) ICH10 - 3A40 ]

     :
                                          PCI Express 1  Intel(R) ICH10 - 3A40
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_8086&DEV_3A40&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,28,0)
      PCI-                                    Intel 82801JB ICH10 - PCI Express Root Port 1

     :
      IRQ                                               17
                                                  FBF00000-FBFFFFFF

  [   /   PCI Express 3  Intel(R) ICH10 - 3A44 ]

     :
                                          PCI Express 3  Intel(R) ICH10 - 3A44
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_8086&DEV_3A44&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,28,2)
      PCI-                                    Intel 82801JB ICH10 - PCI Express Root Port 3

     :
      IRQ                                               18
                                                  FEA00000-FEAFFFFF
                                                    D000-DFFF

  [   /   PCI Express 4  Intel(R) ICH10 - 3A46 ]

     :
                                          PCI Express 4  Intel(R) ICH10 - 3A46
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_8086&DEV_3A46&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,28,3)
      PCI-                                    Intel 82801JB ICH10 - PCI Express Root Port 4

     :
      IRQ                                               19
                                                  FE900000-FE9FFFFF
                                                    C000-CFFF

  [   /   PCI Express 5  Intel(R) ICH10 - 3A48 ]

     :
                                          PCI Express 5  Intel(R) ICH10 - 3A48
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_8086&DEV_3A48&SUBSYS_82D41043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,28,4)
      PCI-                                    Intel 82801JB ICH10 - PCI Express Root Port 5

     :
      IRQ                                               17
                                                  FE800000-FE8FFFFF
                                                    B000-BFFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          compositebus.inf
       ID                                     ROOT\CompositeBus

  [   /    Plug and Play ]

     :
                                           Plug and Play
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     root\swenum

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0000
      PnP-                                    Programmable Interrupt Controller

     :
                                                    0020-0021
                                                    00A0-00A1

  [   /   / ]

     :
                                          /
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0A06
      PnP-                                    Extended IO Bus

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  E0000000-EFFFFFFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  FEC00000-FEC00FFF
                                                  FEE00000-FEE00FFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  FED08000-FED08FFF
                                                  FED1C000-FED1FFFF
                                                  FED20000-FED3FFFF
                                                  FED50000-FED8FFFF
                                                    0010-001F
                                                    0022-003F
                                                    0044-004D
                                                    0050-005F
                                                    0062-0063
                                                    0065-006F
                                                    0072-007F
                                                    0080-0080
                                                    0084-0086
                                                    0088-0088
                                                    008C-008E
                                                    0090-009F
                                                    00A2-00BF
                                                    00E0-00EF
                                                    04D0-04D1
                                                    0500-057F
                                                    0800-087F

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                    0290-029F

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  FFC00000-FFDFFFFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C01
      PnP-                                    System Board Extension

     :
                                                  00000000-0009FFFF
                                                  000C0000-000CFFFF
                                                  000E0000-000FFFFF
                                                  00100000-DFFFFFFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C01
      PnP-                                    System Board Extension

     :
                                                  FED14000-FED19FFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0100
      PnP-                                    System Timer

     :
      IRQ                                               00
                                                    0040-0043

  [   /    ACPI ]

     :
                                           ACPI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\FixedButton

  [   /  PCI ]

     :
                                         PCI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0A08
      PnP-                                    ACPI Three-wire Device Bus

     :
                                                  000A0000-000BFFFF
                                                  000D0000-000DFFFF
                                                  E0000000-FFFFFFFF
                                                    0000-0CF7
                                                    0D00-FFFF

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [  HID (Human Interface Devices) / DeathAdder Mouse ]

     :
                                        DeathAdder Mouse
                                            27.11.2009
                                          1.0.5.0
                                       Razer
      INF-                                          oem10.inf
       ID                                     USB\VID_1532&PID_0016&REV_0100
                                     Port_#0002.Hub_#0007

  [  HID (Human Interface Devices) / HID-   ]

     :
                                        HID-  
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hidserv.inf
       ID                                     HID\GSPYVHid&Col01

  [ -  IEEE 1394 / VIA 1394 OHCI- - ]

     :
                                        VIA 1394 OHCI- -
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          1394.inf
       ID                                     PCI\VEN_1106&DEV_3044&SUBSYS_81FE1043&REV_C0
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(6,3,0)
      PCI-                                    VIA VT6308 Fire IIM IEEE1394 Host Controller

     :
      IRQ                                               19
                                                  FEBFF000-FEBFF7FF
                                                    EC00-EC7F


--------[   ]---------------------------------------------------------------------------------------

     PCI:
       6,  0,  0                   Compex RE100ATX Fast Ethernet Adapter
       0,  30,  0                  Intel 82801JB I/O Controller Hub 10 (ICH10) [A-0]
       0,  31,  5                  Intel 82801JB ICH10 - 2-port SATA Controller
       0,  31,  2                  Intel 82801JB ICH10 - 4-port SATA Controller
       0,  27,  0                  Intel 82801JB ICH10 - High Definition Audio Controller
       0,  28,  0                  Intel 82801JB ICH10 - PCI Express Root Port 1
       0,  28,  2                  Intel 82801JB ICH10 - PCI Express Root Port 3
       0,  28,  3                  Intel 82801JB ICH10 - PCI Express Root Port 4
       0,  28,  4                  Intel 82801JB ICH10 - PCI Express Root Port 5
       0,  31,  3                  Intel 82801JB ICH10 - SMBus Controller
       0,  26,  0                  Intel 82801JB ICH10 - USB Universal Host Controller
       0,  26,  1                  Intel 82801JB ICH10 - USB Universal Host Controller
       0,  26,  2                  Intel 82801JB ICH10 - USB Universal Host Controller
       0,  29,  0                  Intel 82801JB ICH10 - USB Universal Host Controller
       0,  29,  1                  Intel 82801JB ICH10 - USB Universal Host Controller
       0,  29,  2                  Intel 82801JB ICH10 - USB Universal Host Controller
       0,  26,  7                  Intel 82801JB ICH10 - USB2 Enhanced Host Controller
       0,  29,  7                  Intel 82801JB ICH10 - USB2 Enhanced Host Controller
       0,  31,  0                  Intel 82801JB ICH10R - LPC Bridge
       0,  0,  0                   Intel G43/G45/P43/P45 Chipset - Memory Controller Hub [A-2]
       0,  1,  0                   Intel G43/G45/P43/P45 Chipset - Primary PCI Express x16 Root [A-2]
       2,  0,  0                   Marvell 88SE6121 Serial ATA II Host Controller
       3,  0,  0                   Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
       4,  0,  0                   Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
       1,  0,  1                   nVIDIA GF110 - High Definition Audio Controller
       6,  3,  0                   VIA VT6308 Fire IIM IEEE1394 Host Controller
       1,  0,  0                   Zotac GeForce GTX 580 Video Adapter

     PnP:
      PNP0303                                           101/102-Key or MS Natural Keyboard
      PNP0C08                                           ACPI Driver/BIOS
      PNP0A08                                           ACPI Three-wire Device Bus
      PNPA000                                           Adaptec 154x-compatible Controller
      ATK0110                                           Asus ATK-110 ACPI Utility
      PNP0200                                           DMA Controller
      PNP0A06                                           Extended IO Bus
      PNP0700                                           Floppy Disk Controller
      PNP0103                                           High Precision Event Timer
      INT0800                                           Intel Flash EEPROM
      GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_23_-_INTEL(R)_CORE(TM)2_QUAD__CPU___Q9550__@_2.83GHZIntel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz
      GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_23_-_INTEL(R)_CORE(TM)2_QUAD__CPU___Q9550__@_2.83GHZIntel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz
      GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_23_-_INTEL(R)_CORE(TM)2_QUAD__CPU___Q9550__@_2.83GHZIntel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz
      GENUINEINTEL_-_INTEL64_FAMILY_6_MODEL_23_-_INTEL(R)_CORE(TM)2_QUAD__CPU___Q9550__@_2.83GHZIntel(R) Core(TM)2 Quad  CPU   Q9550  @ 2.83GHz
      PNP0C04                                           Numeric Data Processor
      PNP0800                                           PC Speaker
      PNP0C0C                                           Power Button
      PNP0000                                           Programmable Interrupt Controller
      PNP0B00                                           Real-Time Clock
      PNP0C01                                           System Board Extension
      PNP0C01                                           System Board Extension
      PNP0100                                           System Timer
      TEREDO                                            Teredo Tunneling Pseudo-Interface
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      6TO4MP                                             Microsoft 6to4 #2
      6TO4MP                                             Microsoft 6to4
      ISATAP                                             Microsoft ISATAP #2
      ISATAP                                             Microsoft ISATAP #3
      ISATAP                                             Microsoft ISATAP #4
      ISATAP                                             Microsoft ISATAP
      FIXEDBUTTON                                          ACPI

     USB:
      1532 0016                                         DeathAdder Mouse


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ Compex RE100ATX Fast Ethernet Adapter ]

     :
                                      Compex RE100ATX Fast Ethernet Adapter
                                                 PCI
       /  /                        6 / 0 / 0
      ID                                      10EC-8139
                               11F6-8139
                                         0200 (Ethernet Controller)
                                                  10
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

      :
                                                   Compex Corporation
                                     http://www.compex.com/ps.htm
                                       http://www.compex.com/ps.htm
                                     http://www.aida64.com/driver-updates

  [ Intel 82801JB I/O Controller Hub 10 (ICH10) [A-0] ]

     :
                                      Intel 82801JB I/O Controller Hub 10 (ICH10) [A-0]
                                                 PCI
       /  /                        0 / 30 / 0
      ID                                      8086-244E
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  90
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - 2-port SATA Controller ]

     :
                                      Intel 82801JB ICH10 - 2-port SATA Controller
                                                 PCI
       /  /                        0 / 31 / 5
      ID                                      8086-3A26
                               1043-82D4
                                         0101 (IDE Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - 4-port SATA Controller ]

     :
                                      Intel 82801JB ICH10 - 4-port SATA Controller
                                                 PCI
       /  /                        0 / 31 / 2
      ID                                      8086-3A20
                               1043-82D4
                                         0101 (IDE Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - High Definition Audio Controller ]

     :
                                      Intel 82801JB ICH10 - High Definition Audio Controller
                                                 PCI Express 1.0
       /  /                        0 / 27 / 0
      ID                                      8086-3A3E
                               1043-8334
                                         0403 (High Definition Audio)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - PCI Express Root Port 1 ]

     :
                                      Intel 82801JB ICH10 - PCI Express Root Port 1
                                                 PCI
       /  /                        0 / 28 / 0
      ID                                      8086-3A40
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - PCI Express Root Port 3 ]

     :
                                      Intel 82801JB ICH10 - PCI Express Root Port 3
                                                 PCI
       /  /                        0 / 28 / 2
      ID                                      8086-3A44
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - PCI Express Root Port 4 ]

     :
                                      Intel 82801JB ICH10 - PCI Express Root Port 4
                                                 PCI
       /  /                        0 / 28 / 3
      ID                                      8086-3A46
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - PCI Express Root Port 5 ]

     :
                                      Intel 82801JB ICH10 - PCI Express Root Port 5
                                                 PCI
       /  /                        0 / 28 / 4
      ID                                      8086-3A48
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - SMBus Controller ]

     :
                                      Intel 82801JB ICH10 - SMBus Controller
                                                 PCI
       /  /                        0 / 31 / 3
      ID                                      8086-3A30
                               1043-82D4
                                         0C05 (SMBus Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - USB Universal Host Controller ]

     :
                                      Intel 82801JB ICH10 - USB Universal Host Controller
                                                 PCI
       /  /                        0 / 26 / 0
      ID                                      8086-3A37
                               1043-82D4
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - USB Universal Host Controller ]

     :
                                      Intel 82801JB ICH10 - USB Universal Host Controller
                                                 PCI
       /  /                        0 / 26 / 1
      ID                                      8086-3A38
                               1043-82D4
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - USB Universal Host Controller ]

     :
                                      Intel 82801JB ICH10 - USB Universal Host Controller
                                                 PCI
       /  /                        0 / 26 / 2
      ID                                      8086-3A39
                               1043-82D4
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - USB Universal Host Controller ]

     :
                                      Intel 82801JB ICH10 - USB Universal Host Controller
                                                 PCI
       /  /                        0 / 29 / 0
      ID                                      8086-3A34
                               1043-82D4
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - USB Universal Host Controller ]

     :
                                      Intel 82801JB ICH10 - USB Universal Host Controller
                                                 PCI
       /  /                        0 / 29 / 1
      ID                                      8086-3A35
                               1043-82D4
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - USB Universal Host Controller ]

     :
                                      Intel 82801JB ICH10 - USB Universal Host Controller
                                                 PCI
       /  /                        0 / 29 / 2
      ID                                      8086-3A36
                               1043-82D4
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - USB2 Enhanced Host Controller ]

     :
                                      Intel 82801JB ICH10 - USB2 Enhanced Host Controller
                                                 PCI
       /  /                        0 / 26 / 7
      ID                                      8086-3A3C
                               1043-82D4
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10 - USB2 Enhanced Host Controller ]

     :
                                      Intel 82801JB ICH10 - USB2 Enhanced Host Controller
                                                 PCI
       /  /                        0 / 29 / 7
      ID                                      8086-3A3A
                               1043-82D4
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel 82801JB ICH10R - LPC Bridge ]

     :
                                      Intel 82801JB ICH10R - LPC Bridge
                                                 PCI
       /  /                        0 / 31 / 0
      ID                                      8086-3A16
                               1043-82D4
                                         0601 (PCI/ISA Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Intel G43/G45/P43/P45 Chipset - Memory Controller Hub [A-2] ]

     :
                                      Intel G43/G45/P43/P45 Chipset - Memory Controller Hub [A-2]
                                                 PCI
       /  /                        0 / 0 / 0
      ID                                      8086-2E20
                               1043-82D3
                                         0600 (Host/PCI Bridge)
                                                  02
      Fast Back-to-Back Transactions                    , 

     :
      66-                                     
      Bus Mastering                                     

  [ Intel G43/G45/P43/P45 Chipset - Primary PCI Express x16 Root [A-2] ]

     :
                                      Intel G43/G45/P43/P45 Chipset - Primary PCI Express x16 Root [A-2]
                                                 PCI
       /  /                        0 / 1 / 0
      ID                                      8086-2E21
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  02
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Marvell 88SE6121 Serial ATA II Host Controller ]

     :
                                      Marvell 88SE6121 Serial ATA II Host Controller
                                                 PCI Express 1.0 x1
       /  /                        2 / 0 / 0
      ID                                      11AB-6121
                               11AB-6121
                                         0101 (IDE Controller)
                                                  B1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller ]

     :
                                      Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
                                                 PCI Express 1.0 x1
       /  /                        3 / 0 / 0
      ID                                      11AB-4364
                               1043-81F8
                                         0200 (Ethernet Controller)
                                                  12
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

    Vital Product Data (VPD):
                                           Marvell Yukon 88E8056 Gigabit Ethernet Controller
                                           Marvell
                                          Yukon 88E8056
                                                  Rev. 1.2
                                           AbCdEfG78FF72

      :
                                                   Marvell Semiconductor, Inc.
                                     http://www.marvell.com/pc-connectivity
                                       http://www.marvell.com/support
                                     http://www.aida64.com/driver-updates

  [ Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller ]

     :
                                      Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
                                                 PCI Express 1.0 x1
       /  /                        4 / 0 / 0
      ID                                      11AB-4364
                               1043-81F8
                                         0200 (Ethernet Controller)
                                                  12
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

    Vital Product Data (VPD):
                                           Marvell Yukon 88E8056 Gigabit Ethernet Controller
                                           Marvell
                                          Yukon 88E8056
                                                  Rev. 1.2
                                           AbCdEfG69A6E6

      :
                                                   Marvell Semiconductor, Inc.
                                     http://www.marvell.com/pc-connectivity
                                       http://www.marvell.com/support
                                     http://www.aida64.com/driver-updates

  [ nVIDIA GF110 - High Definition Audio Controller ]

     :
                                      nVIDIA GF110 - High Definition Audio Controller
                                                 PCI Express 2.0 x16
       /  /                        1 / 0 / 1
      ID                                      10DE-0E09
                               19DA-1203
                                         0403 (High Definition Audio)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ VIA VT6308 Fire IIM IEEE1394 Host Controller ]

     :
                                      VIA VT6308 Fire IIM IEEE1394 Host Controller
                                                 PCI
       /  /                        6 / 3 / 0
      ID                                      1106-3044
                               1043-81FE
                                         0C00 (FireWire Controller)
                                                  C0
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ Zotac GeForce GTX 580 Video Adapter ]

     :
                                      Zotac GeForce GTX 580 Video Adapter
                                                 PCI Express 2.0 x16
       /  /                        1 / 0 / 0
      ID                                      10DE-1080
                               19DA-1203
                                         0300 (VGA Display Controller)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

     :
                                                   ZOTAC International (MCO) Limited
                                     http://www.zotac.com/index.php?option=com_wrapper&Itemid=483
                                       http://www.zotac.com/index.php?option=com_docman&task=cat_view&gid=44&Itemid=218
                                     http://www.aida64.com/driver-updates


--------[  USB ]----------------------------------------------------------------------------------------------

  [ DeathAdder Mouse (Razer DeathAdder) ]

     :
                                      DeathAdder Mouse
      ID                                      1532-0016
                                         03 / 01 (Human Interface Device)
                                      02
                                           Razer
                                                 Razer DeathAdder
        USB                         2.00
                                         Full  (USB 1.1)


--------[   ]-------------------------------------------------------------------------------------------

    DMA 02                                  
    DMA 04                                   
    IRQ 00                                
    IRQ 01                                 PS/2
    IRQ 06                                  
    IRQ 08                               CMOS  
    IRQ 09                                        AUWTM4QJ IDE Controller
    IRQ 100                              Microsoft ACPI- 
    IRQ 101                              Microsoft ACPI- 
    IRQ 102                              Microsoft ACPI- 
    IRQ 103                              Microsoft ACPI- 
    IRQ 104                              Microsoft ACPI- 
    IRQ 105                              Microsoft ACPI- 
    IRQ 106                              Microsoft ACPI- 
    IRQ 107                              Microsoft ACPI- 
    IRQ 108                              Microsoft ACPI- 
    IRQ 109                              Microsoft ACPI- 
    IRQ 110                              Microsoft ACPI- 
    IRQ 111                              Microsoft ACPI- 
    IRQ 112                              Microsoft ACPI- 
    IRQ 113                              Microsoft ACPI- 
    IRQ 114                              Microsoft ACPI- 
    IRQ 115                              Microsoft ACPI- 
    IRQ 116                              Microsoft ACPI- 
    IRQ 117                              Microsoft ACPI- 
    IRQ 118                              Microsoft ACPI- 
    IRQ 119                              Microsoft ACPI- 
    IRQ 120                              Microsoft ACPI- 
    IRQ 121                              Microsoft ACPI- 
    IRQ 122                              Microsoft ACPI- 
    IRQ 123                              Microsoft ACPI- 
    IRQ 124                              Microsoft ACPI- 
    IRQ 125                              Microsoft ACPI- 
    IRQ 126                              Microsoft ACPI- 
    IRQ 127                              Microsoft ACPI- 
    IRQ 128                              Microsoft ACPI- 
    IRQ 129                              Microsoft ACPI- 
    IRQ 13                                
    IRQ 130                              Microsoft ACPI- 
    IRQ 131                              Microsoft ACPI- 
    IRQ 132                              Microsoft ACPI- 
    IRQ 133                              Microsoft ACPI- 
    IRQ 134                              Microsoft ACPI- 
    IRQ 135                              Microsoft ACPI- 
    IRQ 136                              Microsoft ACPI- 
    IRQ 137                              Microsoft ACPI- 
    IRQ 138                              Microsoft ACPI- 
    IRQ 139                              Microsoft ACPI- 
    IRQ 140                              Microsoft ACPI- 
    IRQ 141                              Microsoft ACPI- 
    IRQ 142                              Microsoft ACPI- 
    IRQ 143                              Microsoft ACPI- 
    IRQ 144                              Microsoft ACPI- 
    IRQ 145                              Microsoft ACPI- 
    IRQ 146                              Microsoft ACPI- 
    IRQ 147                              Microsoft ACPI- 
    IRQ 148                              Microsoft ACPI- 
    IRQ 149                              Microsoft ACPI- 
    IRQ 15                                        Intel(R) ICH10 Family SMBus Controller - 3A30
    IRQ 150                              Microsoft ACPI- 
    IRQ 151                              Microsoft ACPI- 
    IRQ 152                              Microsoft ACPI- 
    IRQ 153                              Microsoft ACPI- 
    IRQ 154                              Microsoft ACPI- 
    IRQ 155                              Microsoft ACPI- 
    IRQ 156                              Microsoft ACPI- 
    IRQ 157                              Microsoft ACPI- 
    IRQ 158                              Microsoft ACPI- 
    IRQ 159                              Microsoft ACPI- 
    IRQ 16                                        Realtek RTL8139/810x Family Fast Ethernet  
    IRQ 16                                        NVIDIA GeForce GTX 580
    IRQ 16                                         - USB   Intel(R) ICH10 - 3A37
    IRQ 16                                          Intel(R) 4 Series Chipset PCI Express - 2E21
    IRQ 16                                           PCI IDE
    IRQ 160                              Microsoft ACPI- 
    IRQ 161                              Microsoft ACPI- 
    IRQ 162                              Microsoft ACPI- 
    IRQ 163                              Microsoft ACPI- 
    IRQ 164                              Microsoft ACPI- 
    IRQ 165                              Microsoft ACPI- 
    IRQ 166                              Microsoft ACPI- 
    IRQ 167                              Microsoft ACPI- 
    IRQ 168                              Microsoft ACPI- 
    IRQ 169                              Microsoft ACPI- 
    IRQ 17                                         High Definition Audio (Microsoft)
    IRQ 17                                          PCI Express 1  Intel(R) ICH10 - 3A40
    IRQ 17                                          PCI Express 5  Intel(R) ICH10 - 3A48
    IRQ 170                              Microsoft ACPI- 
    IRQ 171                              Microsoft ACPI- 
    IRQ 172                              Microsoft ACPI- 
    IRQ 173                              Microsoft ACPI- 
    IRQ 174                              Microsoft ACPI- 
    IRQ 175                              Microsoft ACPI- 
    IRQ 176                              Microsoft ACPI- 
    IRQ 177                              Microsoft ACPI- 
    IRQ 178                              Microsoft ACPI- 
    IRQ 179                              Microsoft ACPI- 
    IRQ 18                                        Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
    IRQ 18                                         - USB   Intel(R) ICH10 - 3A3C
    IRQ 18                                         - USB   Intel(R) ICH10 - 3A36
    IRQ 18                                         - USB   Intel(R) ICH10 - 3A39
    IRQ 18                                          PCI Express 3  Intel(R) ICH10 - 3A44
    IRQ 180                              Microsoft ACPI- 
    IRQ 181                              Microsoft ACPI- 
    IRQ 182                              Microsoft ACPI- 
    IRQ 183                              Microsoft ACPI- 
    IRQ 184                              Microsoft ACPI- 
    IRQ 185                              Microsoft ACPI- 
    IRQ 186                              Microsoft ACPI- 
    IRQ 187                              Microsoft ACPI- 
    IRQ 188                              Microsoft ACPI- 
    IRQ 189                              Microsoft ACPI- 
    IRQ 19                                        Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller #2
    IRQ 19                                         - USB   Intel(R) ICH10 - 3A35
    IRQ 19                                          PCI Express 4  Intel(R) ICH10 - 3A46
    IRQ 19                                        Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
    IRQ 19                                        Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
    IRQ 19                                        VIA 1394 OHCI- -
    IRQ 190                              Microsoft ACPI- 
    IRQ 21                                         - USB   Intel(R) ICH10 - 3A38
    IRQ 22                                         High Definition Audio (Microsoft)
    IRQ 23                                         - USB   Intel(R) ICH10 - 3A3A
    IRQ 23                                         - USB   Intel(R) ICH10 - 3A34
    IRQ 81                               Microsoft ACPI- 
    IRQ 82                               Microsoft ACPI- 
    IRQ 83                               Microsoft ACPI- 
    IRQ 84                               Microsoft ACPI- 
    IRQ 85                               Microsoft ACPI- 
    IRQ 86                               Microsoft ACPI- 
    IRQ 87                               Microsoft ACPI- 
    IRQ 88                               Microsoft ACPI- 
    IRQ 89                               Microsoft ACPI- 
    IRQ 90                               Microsoft ACPI- 
    IRQ 91                               Microsoft ACPI- 
    IRQ 92                               Microsoft ACPI- 
    IRQ 93                               Microsoft ACPI- 
    IRQ 94                               Microsoft ACPI- 
    IRQ 95                               Microsoft ACPI- 
    IRQ 96                               Microsoft ACPI- 
    IRQ 97                               Microsoft ACPI- 
    IRQ 98                               Microsoft ACPI- 
    IRQ 99                               Microsoft ACPI- 
     00000000-0009FFFF              
     000A0000-000BFFFF                      NVIDIA GeForce GTX 580
     000A0000-000BFFFF                       PCI
     000A0000-000BFFFF                 Intel(R) 4 Series Chipset PCI Express - 2E21
     000C0000-000CFFFF              
     000D0000-000DFFFF                       PCI
     000E0000-000FFFFF              
     00100000-DFFFFFFF              
     E0000000-EFFFFFFF               
     E0000000-FFFFFFFF                       PCI
     F0000000-F7FFFFFF             NVIDIA GeForce GTX 580
     F0000000-F9FFFFFF               Intel(R) 4 Series Chipset PCI Express - 2E21
     F8000000-F9FFFFFF             NVIDIA GeForce GTX 580
     FBF00000-FBFFFFFF               PCI Express 1  Intel(R) ICH10 - 3A40
     FCFF8000-FCFFBFFF              High Definition Audio (Microsoft)
     FCFFF400-FCFFF4FF             Intel(R) ICH10 Family SMBus Controller - 3A30
     FCFFF800-FCFFFBFF              - USB   Intel(R) ICH10 - 3A3A
     FCFFFC00-FCFFFFFF              - USB   Intel(R) ICH10 - 3A3C
     FD000000-FDFFFFFF             NVIDIA GeForce GTX 580
     FD000000-FE7FFFFF               Intel(R) 4 Series Chipset PCI Express - 2E21
     FE7FC000-FE7FFFFF              High Definition Audio (Microsoft)
     FE800000-FE8FFFFF               PCI Express 5  Intel(R) ICH10 - 3A48
     FE8FFC00-FE8FFFFF                PCI IDE
     FE900000-FE9FFFFF               PCI Express 4  Intel(R) ICH10 - 3A46
     FE9FC000-FE9FFFFF             Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller #2
     FEA00000-FEAFFFFF               PCI Express 3  Intel(R) ICH10 - 3A44
     FEAFC000-FEAFFFFF             Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
     FEB00000-FEBFFFFF             Intel(R) 82801 PCI  - 244E
     FEBFF000-FEBFF7FF             VIA 1394 OHCI- -
     FEBFFC00-FEBFFCFF             Realtek RTL8139/810x Family Fast Ethernet  
     FEC00000-FEC00FFF               
     FED00000-FED003FF               
     FED08000-FED08FFF               
     FED14000-FED19FFF              
     FED1C000-FED1FFFF               
     FED20000-FED3FFFF               
     FED50000-FED8FFFF               
     FEE00000-FEE00FFF               
     FFA00000-FFBFFFFF             Intel(R) 82802 Firmware 
     FFC00000-FFDFFFFF               
     FFE00000-FFFFFFFF             Intel(R) 82802 Firmware 
     0000-000F                           
     0000-0CF7                                 PCI
     0010-001F                         
     0020-0021                         
     0022-003F                         
     0040-0043                        
     0044-004D                         
     0050-005F                         
     0060-0060                         PS/2
     0061-0061                        
     0062-0063                         
     0064-0064                         PS/2
     0065-006F                         
     0070-0071                       CMOS  
     0072-007F                         
     0080-0080                         
     0081-0083                           
     0084-0086                         
     0087-0087                           
     0088-0088                         
     0089-008B                           
     008C-008E                         
     008F-008F                           
     0090-009F                         
     00A0-00A1                         
     00A2-00BF                         
     00C0-00DF                           
     00E0-00EF                         
     00F0-00FF                        
     0290-029F                         
     03B0-03BB                                NVIDIA GeForce GTX 580
     03B0-03BB                           Intel(R) 4 Series Chipset PCI Express - 2E21
     03C0-03DF                                NVIDIA GeForce GTX 580
     03C0-03DF                           Intel(R) 4 Series Chipset PCI Express - 2E21
     03F0-03F5                          
     03F7-03F7                          
     0400-041F                       Intel(R) ICH10 Family SMBus Controller - 3A30
     04D0-04D1                         
     0500-057F                         
     0800-087F                         
     0D00-FFFF                                 PCI
     7400-740F                       Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
     7480-748F                       Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
     7800-7803                       Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
     7880-7887                       Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
     7C00-7C03                       Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
     8000-8007                       Intel(R) ICH10 Family 4 port Serial ATA Storage Controller 1 - 3A20
     8400-840F                       Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
     8480-848F                       Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
     8800-8803                       Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
     8880-8887                       Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
     8C00-8C03                       Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
     9000-9007                       Intel(R) ICH10 Family 2 port Serial ATA Storage Controller 2 - 3A26
     9080-909F                        - USB   Intel(R) ICH10 - 3A34
     9400-941F                        - USB   Intel(R) ICH10 - 3A35
     9480-949F                        - USB   Intel(R) ICH10 - 3A36
     9800-981F                        - USB   Intel(R) ICH10 - 3A37
     9880-989F                        - USB   Intel(R) ICH10 - 3A38
     9C00-9C1F                        - USB   Intel(R) ICH10 - 3A39
     A000-AFFF                         Intel(R) 4 Series Chipset PCI Express - 2E21
     AC00-AC7F                       NVIDIA GeForce GTX 580
     B000-BFFF                         PCI Express 5  Intel(R) ICH10 - 3A48
     B400-B40F                          PCI IDE
     B480-B483                          PCI IDE
     B800-B807                          PCI IDE
     B880-B883                          PCI IDE
     BC00-BC07                          PCI IDE
     C000-CFFF                         PCI Express 4  Intel(R) ICH10 - 3A46
     C800-C8FF                       Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller #2
     D000-DFFF                         PCI Express 3  Intel(R) ICH10 - 3A44
     D800-D8FF                       Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
     E000-EFFF                       Intel(R) 82801 PCI  - 244E
     E800-E8FF                       Realtek RTL8139/810x Family Fast Ethernet  
     EC00-EC7F                       VIA 1394 OHCI- -
     FFE0-FFEF                       AUWTM4QJ IDE Controller


--------[  ]--------------------------------------------------------------------------------------------------------

  [  HID ]

     :
                                       HID
                                           IBM enhanced (101- or 102-key) keyboard
                                     Russian
        ANSI                             1251 - @%SystemRoot%\system32\mlang.dll,-4611
        OEM                              866 - @%SystemRoot%\system32\mlang.dll,-4645
                                         1
                                         31

  [ HID-  ]

     :
                                            HID- 
                                         8
                                              
                                         0
                                     500 msec
       X / Y                                       0 / 0
                                 3

     :
                               
      ''                                
                
                                            
                   
                                              
      Sonar                                             


--------[  ]----------------------------------------------------------------------------------------------------

  [ Fax ]

     :
                                             Fax
                                      
                                  
                                            SHRFAX:
                                         Microsoft Shared Fax Driver (v4.00)
                                           Fax
                                         winprint
                                     
                                             4:00 - 4:00
                                               1
                                 0
                                                  

     :
                                            Letter, 8.5 x 11 in
                                              
                                          200 x 200 dpi Mono

  [ HP Officejet 4300 Series ( ) ]

     :
                                             HP Officejet 4300 Series
                                      
                                  
                                            USB001
                                         HP Officejet 4300 Series (v6.00)
                                           HP Officejet 4300 Series
                                         hpzppwn7
                                     
                                             4:00 - 4:00
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color

     :
                                                   Hewlett-Packard Company
                                     http://www.hp.com/united-states/consumer/gateway/printing_multifunction.html
                                     http://www.aida64.com/driver-updates

  [ Microsoft XPS Document Writer ]

     :
                                             Microsoft XPS Document Writer
                                      
                                  
                                            XPSPort:
                                         Microsoft XPS Document Writer (v6.00)
                                           Microsoft XPS Document Writer
                                         winprint
                                     
                                             4:00 - 4:00
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color


--------[  ]------------------------------------------------------------------------------------------------

    Adobe ARM                          Registry\Common\Run      C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe 
    DeathAdder                         Registry\Common\Run      C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe 
    egui                               Registry\Common\Run      C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice
    icq                                Registry\User\Run        C:\Program Files (x86)\ICQLite\icq.exe silent
    Octoshape Streaming Services       Registry\User\Run        C:\Users\Aparratus\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe -inv:bootrun
    Origin                             Registry\Common\Run      D:\Games\Origin\Origin.exe 
    QuickTime Task                     Registry\Common\Run      C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime
    RunDLLEntry                        Registry\Common\Run      C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry
    SoundMAXPnP                        Registry\Common\Run      C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe 
    SunJavaUpdateSched                 Registry\Common\Run      C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 
    UpdReg                             Registry\Common\Run      C:\Windows\UpdReg.EXE 
    VolPanel                           Registry\Common\Run      C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe /r


--------[  ]---------------------------------------------------------------------------------------------

  [ GoogleUpdateTaskMachineCore ]

     :
                                               GoogleUpdateTaskMachineCore
                                                  
                                           C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                                     /c
                                            
                                               ,    Google  .      ,   Google   .      ,     ,     .    ,    Google,   .
                                        
                                               Aparratus
                                         02.11.2011 21:39:36
                                         03.11.2011 13:25:00

     :
       #1                                            
       #2                                         13:25, ,   03.06.2011

  [ GoogleUpdateTaskMachineUA ]

     :
                                               GoogleUpdateTaskMachineUA
                                                  
                                           C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                                     /ua /installsource scheduler
                                            
                                               ,    Google  .      ,   Google   .      ,     ,     .    ,    Google,   .
                                        
                                               Aparratus
                                         02.11.2011 22:25:00
                                         02.11.2011 23:25:00

     :
       #1                                         1 .  13:25  24 . ,   03.06.2011


--------[   ]-------------------------------------------------------------------------------------

    Torrent                                                                                     1.8.5  
    Adobe Flash Player 10 ActiveX                                                           10.0.22.87  
    Adobe Flash Player 11 Plugin                                                            11.0.1.152  
    Adobe Reader X (10.1.1) - Russian [ ()]                                        10.1.1  
    AIDA64 Extreme Edition v1.85.1600                                                        1.85.1600  
    Apple Application Support                                                                    1.2.1  
    Apple Software Update [ ()]                                                 2.1.1.116  
    ASUSUpdate                                                                                          
    Batch Converter Plug-In                                                                      4.0.4  
    Battlefield 3                                                                             1.0.0.0  
    Battlefield: Bad Company 2                                                                1.0.0.0  
    Battlelog Web Plugins                                                                       1.96.0  
    Bing Bar                                                                                 7.0.822.0  
    CCleaner                                                                                      3.07  
    Counter Strike 1.6 Original Game                                                                    
    Defraggler                                                                                    2.05  
    DNA                                                                                  2.2.4 (16502)  
    DNA                                                                                  2.2.4 (16502)  
    DriverAgent by eSupport.com                                                                         
    EPU-6 Engine                                                                               1.01.17  
    ESET NOD32 Antivirus [ ()]                                                   4.2.71.3  
    ESN Sonar                                                                                   0.70.0  
    ESN Sonar                                                                                   0.70.3  
    File Streamer Plug-In                                                                        4.1.1  
    Fraps                                                                                               
    Gears of War                                                                             1.00.0000  
    GOM Player                                                                             2.1.27.5031  
    ICQ Lite []                                                                            7  
    Java Auto Updater                                                                          2.0.6.1  
    Java(TM) 6 Update 29                                                                       6.0.290  
    K-Lite Mega Codec Pack 7.2.0                                                                 7.2.0  
    Left 4 Dead 2                                                                                       
    Marvell Miniport Driver                                                                  11.10.5.3  
    Microsoft .NET Framework 4 Client Profile RUS Language Pack [ ()]           4.0.30319  
    Microsoft .NET Framework 4 Client Profile                                                4.0.30319  
    Microsoft .NET Framework 4 Client Profile                                                4.0.30319  
    Microsoft .NET Framework 4 Extended                                                      4.0.30319  
    Microsoft .NET Framework 4 Extended                                                      4.0.30319  
    Microsoft Games for Windows - LIVE Redistributable                                        3.5.88.0  
    Microsoft Games for Windows Marketplace                                                   3.5.50.0  
    Microsoft Primary Interoperability Assemblies 2005                                    8.0.50727.42  
    Microsoft Visual C++ 2005 Redistributable (x64)                                          8.0.56336  
    Microsoft Visual C++ 2005 Redistributable                                                8.0.59193  
    Microsoft Visual C++ 2005 Redistributable                                                8.0.61001  
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 [ ()]             9.0.21022  
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022                                9.0.21022  
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17                             9.0.30729  
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161                      9.0.30729.6161  
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022                                9.0.21022  
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 [ ()]             9.0.30729  
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17                             9.0.30729  
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148                      9.0.30729.4148  
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161                      9.0.30729.6161  
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219                             10.0.40219  
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319                             10.0.30319  
    Microsoft Windows Media Video 9 VCM                                                                 
    Microsoft XNA Framework Redistributable 3.1                                            3.1.10527.0  
    Might & Magic Heroes VI                                                                             
    Mozilla Firefox (3.6.6)                                                                 3.6.6 (ru)  
    Mozilla Firefox 7.0.1 (x86 ru)                                                               7.0.1  
    Mozilla Firefox 7.0.1 (x86 ru)                                                               7.0.1  
    MSXML 4.0 SP2 (KB954430)                                                               4.20.9870.0  
    MSXML 4.0 SP2 (KB973688)                                                               4.20.9876.0  
    NVIDIA Install Application [ ()]                                        2.1002.46.235  
    NVIDIA PhysX                                                                             9.11.0621  
    NVIDIA Stereoscopic 3D Driver                                                         7.17.12.8562  
    NVIDIA Update Components [ ()]                                                 1.5.20  
    NVIDIA  HD 1.2.24.0 [ ()]                                        1.2.24.0  
    NVIDIA   285.62 [ ()]                                        285.62  
    NVIDIA  3D Vision 285.62 [ ()]                                          285.62  
    NVIDIA   3D Vision 285.62 [ ()]                              285.62  
    NVIDIA    PhysX 9.11.0621 [ ()]              9.11.0621  
    Octoshape add-in for Adobe Flash Player                                                             
    Octoshape add-in for Adobe Flash Player                                                             
    Octoshape Streaming Services                                                                        
    Octoshape Streaming Services                                                                        
    OpenAL                                                                                              
    OpenOffice.org 3.0 [ ()]                                                     3.0.9358  
    Origin                                                                                     8.3.1.9  
    P2PFilter 3.0.5                                                                              3.0.5  
    PFPortChecker 1.0.39                                                                        1.0.39  
    Project Zomboid [ ()]                                                           1.0.0  
    PunkBuster Services                                                                                 
    QuickTime [ ()]                                                             7.66.71.0  
    Razer DeathAdder(TM) Mouse []                                                       3.00  
    SAMSUNG Mobile Modem Driver Set                                                                     
    Samsung Mobile phone USB driver Drive Software                                                      
    SAMSUNG Mobile USB Modem 1.0 Software                                                               
    SAMSUNG Mobile USB Modem Software                                                                   
    Samsung PC Studio 3 []                                                          3.2.1.80206  
    Samsung PC Studio 3 USB Driver Installer []                                     3.2.0.70701  
    Samsung PC Studio 3                                                                    3.0.0.80206  
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)                        1  
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)                        1  
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)                        1  
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)                        1  
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)                        1  
    Security Update for Microsoft .NET Framework 4 Extended (KB2416472)                              1  
    Security Update for Microsoft .NET Framework 4 Extended (KB2487367)                              1  
    Security Update for     Microsoft.NET Framework 4 - RUS (KB2478663)                 1  
    Security Update for     Microsoft.NET Framework 4 - RUS (KB2518870)                 1  
    Skype 5.5                                                                                 5.5.124  
    Sound Blaster X-Fi MB                                                                          1.0  
    SoundMAX []                                                                     6.10.2.6600  
    StarCraft II                                                                           1.4.1.19776  
    Steam                                                                                      1.0.0.0  
    StrongDC++ sqlite x64                                                                               
    System Requirements Lab CYRI                                                              4.4.26.0  
    Text-To-VoIP Plug-in                                                                         4.0.0  
    The Witcher 2.Assassins Of Kings.v 1.3 + 9 DLC                                    The Witcher 2.Assassins Of Kings.v 1.3 + 9 DLC  
    Total War: SHOGUN 2                                                                                 
    Tunngle beta                                                                                        
    Ubisoft Game Launcher [ ()]                                                      0119  
    Ubisoft Game Launcher                                                                         0119  
    Ubisoft Game Launcher                                                                         0119  
    Ubisoft Game Launcher                                                                      1.0.0.0  
    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)                                 1  
    Ventrilo Client for Windows x64                                                            3.0.5.0  
    VKSaver                                                                                      2.2.2  
    Voice Splicer Plug-In                                                                        4.2.7  
    Winamp 5.6.0.3091 Pro Full [ ()]                                           5.6.0.3091  
    Windows Live ID Sign-in Assistant                                                     6.500.3165.0  
    Windows Media Player Firefox Plugin                                                        1.0.0.8  
    Workplace Backgrounds                                                                        1.0.0  
     WinRAR                                                                                    
     NVIDIA 1.5.20 [ ()]                                                 1.5.20  
      NVIDIA 285.62 [ ()]                                          285.62  
        Microsoft.NET Framework 4 - RUS                       4.0.30319  


--------[  ]----------------------------------------------------------------------------------------------------

    Microsoft Internet Explorer 8.0.7600.16385                              22TKD-F8XX6-YG69F-9M66D-PMJBM
    Microsoft Windows 7 Ultimate                                            22TKD-F8XX6-YG69F-9M66D-PMJBM
    mIRC                                                                    5225-401373


--------[   ]-------------------------------------------------------------------------------------------------

    .669                Composer 669                                    
    .AAC               MPEG-2 AAC                                                  
    .AIF               Apple Audio Interchange                                     
    .AIFF              Apple Audio Interchange                                     
    .AMF                DSMI AMF                                        
    .ASF              Advanced Streaming Format                                        
    .ASX                Winamp                                    
    .AU                  Audio Units                                
    .AUD                 AUD                                        
    .AVI                AVI                                                 
    .AVR               Audio Visual Research                                       
    .B4S                Winamp                                    
    .CAF               Apple Core Audio                                          
    .CDA                -                                      
    .FAR                Farandole Composer                              
    .FLAC              FLAC                                                        
    .FLV                Flash                                                 
    .HTK               Hidden Markov Model Toolkit Speech Recognition              
    .IFF               Apple Audio Interchange                                     
    .IT                 Impulsetracker                                  
    .ITZ                 Impulsetracker                           
    .KAR               MIDI                                              
    .M2V                MPEG-2                                              
    .M3U                Winamp                                    
    .M3U8               Winamp                                    
    .M4A                 MPEG-4                                        
    .MAT                Matlab                                              
    .MDZ                 Protracker                               
    .MID                MIDI                                                
    .MIDI               MIDI                                                
    .MIZ                MIDI                                                 
    .MKV                Matroska                                            
    .MOD                Protracker                                      
    .MP1                MPEG Layer-1                                       
    .MP2                MPEG Layer-2                                       
    .MP3                MPEG Layer-3                                       
    .MP4                MPEG-4                                              
    .MPEG               MPEG                                                
    .MPG                MPEG                                                
    .MTM                Multitracker                                    
    .NSA                  Nullsoft                           
    .NST                NoiseTracker                                    
    .NSV                  Nullsoft                           
    .OGG               Ogg Vorbis                                                  
    .OKT                Amiga Oktalyzer                                 
    .PAF                Paris                                              
    .PLS                Winamp                                    
    .PTM                PolyTracker                                     
    .PVF               Portable Voice Format                                       
    .RAW                             
    .RF64                RIFF 64                     
    .RMI                MIDI                                                
    .S3M                Screamtracker 3                                 
    .S3Z                 Screamtracker 3                          
    .SD2                Sound Designer II                                  
    .SDS                  MIDI     
    .SF                 IRCAM                                              
    .STM                Screamtracker 2                                 
    .STZ                 Screamtracker 2                          
    .SWF              Shockwave Flash                                                  
    .ULT                Ultratracker                                    
    .VLB               Dolby VLB AAC                                               
    .VOC               Creative VOC                                              
    .W64               Soundforge Wow 64                                         
    .WAL                 Winamp                              
    .WAV               WAVE                                                        
    .WEBM               WebM                                                
    .WLZ                 Winamp                                   
    .WMA               Windows Media Audio                                         
    .WMV               Windows Media Video                                         
    .WPL                Winamp                                    
    .WSZ                 Winamp                              
    .WV                WavPack                                                     
    .WVE               WAVE                                                        
    .XI                  Fasttracker 2                              
    .XM                 Fasttracker 2                                   
    .XMZ                 Fasttracker 2                            
    386               Virtual Device Driver                                            
    3G2               3GPP2 Movie                                                      video/3gpp2
    3GP               3GP File                                                         video/3gpp
    3GP2              3GPP2 Movie                                                      video/3gpp2
    3GPP              3GPP File                                                        video/3gpp
    7Z                 WinRAR                                                     
    AAC               AAC File                                                         audio/aac
    AC3               AC3 Audio                                                        audio/ac3
    ACE                WinRAR                                                     
    ACROBATSECURITYSETTINGS  Adobe Acrobat Security Settings Document                         application/vnd.adobe.acrobat-security-settings
    ADT               ADTS Audio                                                       audio/vnd.dlna.adts
    ADTS              ADTS File                                                        audio/aac
    AIF               AIFF Audio                                                       audio/aiff
    AIFC              AIFF Audio                                                       audio/aiff
    AIFF              AIFF Audio                                                       audio/aiff
    AMC               AMC Movie                                                        application/x-mpeg
    ANI               Animated Cursor                                                  
    API               API File                                                         
    APPLICATION       Application Manifest                                             application/x-ms-application
    APPREF-MS         Application Reference                                            
    ARJ                WinRAR                                                     
    ASA               ASA File                                                         
    ASF               ASF File                                                         video/x-ms-asf
    ASP               ASP File                                                         
    ASX               GOM Media file(.asx)                                             video/x-ms-asf
    AU                AU Format Sound                                                  audio/basic
    AVI               AVI Video File                                                   video/avi
    BAT               Windows Batch File                                               
    BAU                 OpenOffice.org 1.1                                
    BLG               Performance Monitor File                                         
    BMP               Bitmap Image                                                     image/bmp
    BSP               BSP File                                                         
    BZ                 WinRAR                                                     
    BZ2                WinRAR                                                     
    C2R               C2R File                                                         
    CAB                WinRAR                                                     
    CAF               CAF Audio                                                        audio/x-caf
    CAMP              WCS Viewing Condition Profile                                    
    CAT               Security Catalog                                                 application/vnd.ms-pki.seccat
    CDA               CD Audio Track                                                   
    CDDA              AIFF Audio                                                       audio/aiff
    CDMP              WCS Device Profile                                               
    CDX               CDX File                                                         
    CER               Security Certificate                                             application/x-x509-ca-cert
    CHESSTITANSSAVE-MS  .ChessTitansSave-ms                                              
    CHK               Recovered File Fragments                                         
    CHM               Compiled HTML Help file                                          
    CMD               Windows Command Script                                           
    COM               MS-DOS Application                                               
    COMFYCAKESSAVE-MS  .ComfyCakesSave-ms                                               
    COMPOSITEFONT     Composite Font File                                              
    CONTACT           Contact File                                                     text/x-ms-contact
    CPL               Control Panel Item                                               
    CRD               Information Card                                                 
    CRDS              Information Card Store                                           
    CRL               Certificate Revocation List                                      application/pkix-crl
    CRT               Security Certificate                                             application/x-x509-ca-cert
    CSS               Cascading Style Sheet Document                                   text/css
    CUR               Cursor                                                           
    DAT               GOM Media file(.dat)                                             
    DB                Data Base File                                                   
    DEM               DEM File                                                         
    DER               Security Certificate                                             application/x-x509-ca-cert
    DESKLINK          Desktop Shortcut                                                 
    DIAGCAB           Diagnostic Cabinet                                               
    DIAGCFG           Diagnostic Configuration                                         
    DIAGPKG           Diagnostic Document                                              
    DIB               Bitmap Image                                                     image/bmp
    DIF               DV Movie                                                         video/x-dv
    DIVX              DIVX Video File                                                  video/avi
    DLL               Application Extension                                            application/x-msdownload
    DMB               GOM Media file(.dmb)                                             
    DMSKM             GOM Media file(.dmskm)                                           
    DOC                Microsoft Word 97-2003                                  
    DOCM               Microsoft Word                                          
    DOCX              OOXML Text Document                                              
    DOT                Microsoft Word 97-2003                                    
    DOTM               Microsoft Word                                            
    DOTX               Microsoft Word                                            
    DRV               Device Driver                                                    
    DSN               Microsoft OLE DB Provider for ODBC Drivers                       
    DV                DV Movie                                                         video/x-dv
    DVR               Microsoft Recorded TV Show                                       
    DVR-MS            Microsoft Recorded TV Show                                       
    DWFX              XPS Document                                                     model/vnd.dwfx+xps
    EASMX             XPS Document                                                     model/vnd.easmx+xps
    EDRWX             XPS Document                                                     model/vnd.edrwx+xps
    EMF               EMF File                                                         
    EPRTX             XPS Document                                                     model/vnd.eprtx+xps
    EVT               EVT File                                                         
    EVTX              EVTX File                                                        
    EXE               Application                                                      application/x-msdownload
    FDF                 Adobe Acrobat                                      application/vnd.fdf
    FLV               Flash Video File                                                 
    FON               Font file                                                        
    FREECELLSAVE-MS   .FreeCellSave-ms                                                 
    GADGET            Windows Gadget                                                   
    GIF               GIF Image                                                        image/gif
    GMMP              WCS Gamut Mapping Profile                                        
    GOM               GOM Media file(.gom)                                             
    GPS               Gomplayer Skin File                                              application/x-gom-skin
    GROUP             Contact Group File                                               text/x-ms-group
    GRP               Microsoft Program Group                                          
    GSM               GSM Audio                                                        audio/x-gsm
    GZ                 WinRAR                                                     
    H1C               Windows Help Collection Definition File                          
    H1D               Windows Help Validator File                                      
    H1F               Windows Help Include File                                        
    H1H               Windows Help Merged Hierarchy                                    
    H1K               Windows Help Index File                                          
    H1Q               Windows Help Merged Query Index                                  
    H1S               Compiled Windows Help file                                       
    H1T               Windows Help Table of Contents File                              
    H1V               Windows Help Virtual Topic Definition File                       
    H1W               Windows Help Merged Keyword Index                                
    HDMOV             HDMOV Video File                                                 video/quicktime
    HEARTSSAVE-MS     .HeartsSave-ms                                                   
    HLP               Help File                                                        
    HTA               HTML Application                                                 application/hta
    HTM               HTML Document                                                    text/html
    HTML              HTML Document                                                    text/html
    ICC               ICC Profile                                                      
    ICL               Icon Library                                                     
    ICM               ICC Profile                                                      
    ICO               Icon                                                             image/x-icon
    IFO               DVD IFO File                                                     
    IMG               Disc Image File                                                  
    INF               Setup Information                                                
    INI               Configuration Settings                                           
    ISO               Disc Image File                                                  
    JAR               Executable Jar File                                              
    JFIF              JPEG Image                                                       image/jpeg
    JNLP              JNLP File                                                        application/x-java-jnlp-file
    JNT               Journal Document                                                 
    JOB               Task Scheduler Task Object                                       
    JOD               Microsoft.Jet.OLEDB.4.0                                          
    JPE               JPEG Image                                                       image/jpeg
    JPEG              JPEG Image                                                       image/jpeg
    JPG               JPEG Image                                                       image/jpeg
    JPS               JPS File                                                         image/jps
    JS                JScript Script File                                              
    JSE               JScript Encoded File                                             
    JTP               Journal Template                                                 
    JTX               XPS Document                                                     application/x-jtx+xps
    K3G               GOM Media file(.k3g)                                             
    LABEL             Property List                                                    
    LHA                WinRAR                                                     
    LIBRARY-MS        Library Folder                                                   application/windows-library+xml
    LMP4              GOM Media file(.lmp4)                                            
    LNK               Shortcut                                                         
    LOG               Text Document                                                    
    LZH                WinRAR                                                     
    M1V               MPEG Video File                                                  video/mpeg
    M2P               MPEG Video File                                                  video/mpeg
    M2T               MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    M2TS              MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    M2V               MPEG Video File                                                  video/mpeg
    M3U               M3U file                                                         audio/x-mpegurl
    M4A               AAC                                                         audio/x-m4a
    M4B               AAC                                                    audio/x-m4b
    M4P               AAC  ()                                           audio/x-m4p
    M4V               M4V Video File                                                   /x-m4v
    MAC               MacPaint Image                                                   image/x-macpaint
    MAHJONGTITANSSAVE-MS  .MahjongTitansSave-ms                                            
    MAPIMAIL          Mail Service                                                     
    MCL               MCL File                                                         
    MDF               MDF File                                                         
    MDS               MDS File                                                         
    MDX               MDX File                                                         
    MFP               Macromedia Flash Paper                                           application/x-shockwave-flash
    MHT               MHTML Document                                                   message/rfc822
    MHTML             MHTML Document                                                   message/rfc822
    MID               MIDI Sequence                                                    audio/mid
    MIDI              MIDI Sequence                                                    audio/mid
    MIG               Migration Store                                                  
    MINESWEEPERSAVE-MS  .MinesweeperSave-ms                                              
    MLC               Language Pack File_                                              
    MOD               Movie Clip                                                       video/mpeg
    MOV               GOM Media file(.mov)                                             video/quicktime
    MP2               MP3 Format Sound                                                 audio/mpeg
    MP2V              MPEG Video File                                                  video/mpeg
    MP3               MP3 Format Sound                                                 audio/mpeg
    MP4               MP4 Video File                                                   video/mp4
    MP4V              MP4V Video File                                                  video/mp4
    MPA               Movie Clip                                                       video/mpeg
    MPCPL             MPC Playlist File                                                
    MPE               MPEG Video File                                                  video/mpeg
    MPEG              MPEG Video File                                                  video/mpeg
    MPG               MPEG Video File                                                  video/mpeg
    MPLS              Blu-ray Playlist File                                            
    MPO               MPO File                                                         image/mpo
    MPV2              MPEG Video File                                                  video/mpeg
    MPV4              MPV4 Video File                                                  video/mpeg
    MQV               GOM Media file(.mqv)                                             video/quicktime
    MSC               Microsoft Common Console Document                                
    MSDVD             MSDVD File                                                       
    MSI               Windows Installer Package                                        
    MSP               Windows Installer Patch                                          
    MSRCINCIDENT      Windows Remote Assistance Invitation                             
    MSSTYLES          Windows Visual Style File                                        
    MSU               Microsoft Update Standalone Package                              
    MTS               MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    MYDOCS            MyDocs Drop Target                                               
    NFO               MSInfo Configuration File                                        
    OCX               ActiveX control                                                  
    ODB                 OpenDocument                                         application/vnd.sun.xml.base
    ODF                OpenDocument                                             application/vnd.oasis.opendocument.formula
    ODG                OpenDocument                                             application/vnd.oasis.opendocument.graphics
    ODM                 OpenDocument                                  application/vnd.oasis.opendocument.text-master
    ODP                OpenDocument                                         application/vnd.oasis.opendocument.presentation
    ODS                 OpenDocument                                 application/vnd.oasis.opendocument.spreadsheet
    ODT                 OpenDocument                                  application/vnd.oasis.opendocument.text
    OGM               Ogg Video File                                                   video/x-ogm
    OGV               Ogg Video File                                                   
    OSDX              OpenSearch Description File                                      application/opensearchdescription+xml
    OTF               OpenType Font file                                               
    OTG                 OpenDocument                                      application/vnd.oasis.opendocument.graphics-template
    OTH                HTML-                                            application/vnd.oasis.opendocument.text-web
    OTP                 OpenDocument                                  application/vnd.oasis.opendocument.presentation-template
    OTS                  OpenDocument                          application/vnd.oasis.opendocument.spreadsheet-template
    OTT                  OpenDocument                         application/vnd.oasis.opendocument.text-template
    OXT               OpenOffice.org Extension                                         application/vnd.openofficeorg.extension
    P10               Certificate Request                                              application/pkcs10
    P12               Personal Information Exchange                                    application/x-pkcs12
    P7B               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    P7C               Digital ID File                                                  application/pkcs7-mime
    P7M               PKCS #7 MIME Message                                             application/pkcs7-mime
    P7R               Certificate Request Response                                     application/x-pkcs7-certreqresp
    P7S               PKCS #7 Signature                                                application/pkcs7-signature
    PBK               Dial-Up Phonebook                                                
    PCT               PICT Image                                                       image/pict
    PDF               Adobe Acrobat Document                                           application/pdf
    PDFXML            Adobe Acrobat PDFXML Document                                    application/vnd.adobe.pdfxml
    PDX                Acrobat Catalog                                           application/vnd.adobe.pdx
    PERFMONCFG        Performance Monitor Configuration                                
    PFM               Type 1 Font file                                                 
    PFX               Personal Information Exchange                                    application/x-pkcs12
    PIC               PICT Image                                                       image/pict
    PICT              PICT Image                                                       image/pict
    PIF               Shortcut to MS-DOS Program                                       
    PKO               Public Key Security Object                                       application/vnd.ms-pki.pko
    PLIST             QuickTime Preferences                                            
    PNF               Precompiled Setup Information                                    
    PNG               PNG Image                                                        image/png
    PNS               PNS File                                                         image/pns
    PNT               MacPaint Image                                                   image/x-macpaint
    PNTG              MacPaint Image                                                   image/x-macpaint
    POT                Microsoft PowerPoint 97-2003                              
    POTM               Microsoft PowerPoint                                      
    POTX               Microsoft PowerPoint                                      
    PPS                Microsoft PowerPoint                                
    PPT                Microsoft PowerPoint 97-2003                         
    PPTM               Microsoft PowerPoint                                 
    PPTX               Microsoft PowerPoint                                 
    PRF               PICS Rules File                                                  application/pics-rules
    PRINTEREXPORT     Printer Migration File                                           
    PS1               PS1 File                                                         
    PS1XML            PS1XML File                                                      
    PSC1              PSC1 File                                                        application/PowerShell
    PSD1              PSD1 File                                                        
    PSM1              PSM1 File                                                        
    PURBLEPAIRSSAVE-MS  .PurblePairsSave-ms                                              
    PURBLESHOPSAVE-MS  .PurbleShopSave-ms                                               
    QDS               Directory Query                                                  
    QHT               QHT File                                                         text/x-html-insertion
    QHTM              QHTM File                                                        text/x-html-insertion
    QPA               QuickTime Player Addition                                        
    QT                 QuickTime                                                  video/quicktime
    QTI               QuickTime Image                                                  image/x-quicktime
    QTIF              QuickTime Image                                                  image/x-quicktime
    QTL                QuickTime                                                  application/x-quicktimeplayer
    QTP               QuickTime Preferences                                            
    QTR               QuickTime Resources                                              
    QTS               QuickTime                                                        
    QTX               QuickTime Extension                                              
    R00                WinRAR                                                     
    R01                WinRAR                                                     
    R02                WinRAR                                                     
    R03                WinRAR                                                     
    R04                WinRAR                                                     
    R05                WinRAR                                                     
    R06                WinRAR                                                     
    R07                WinRAR                                                     
    R08                WinRAR                                                     
    R09                WinRAR                                                     
    R10                WinRAR                                                     
    R11                WinRAR                                                     
    R12                WinRAR                                                     
    R13                WinRAR                                                     
    R14                WinRAR                                                     
    R15                WinRAR                                                     
    R16                WinRAR                                                     
    R17                WinRAR                                                     
    R18                WinRAR                                                     
    R19                WinRAR                                                     
    R20                WinRAR                                                     
    R21                WinRAR                                                     
    R22                WinRAR                                                     
    R23                WinRAR                                                     
    R24                WinRAR                                                     
    R25                WinRAR                                                     
    R26                WinRAR                                                     
    R27                WinRAR                                                     
    R28                WinRAR                                                     
    R29                WinRAR                                                     
    RAR                WinRAR                                                     
    RAT               Rating System File                                               application/rat-file
    RDP               Remote Desktop Connection                                        
    REG               Registration Entries                                             
    RESMONCFG         Resource Monitor Configuration                                   
    REV                RAR                                         
    RLE               RLE File                                                         
    RLL               Application Extension                                            
    RM                RealMedia Video File                                             application/vnd.rn-realmedia
    RMI               MIDI Sequence                                                    audio/mid
    RMVB              RealMedia Video File                                             video/vnd.rn-realvideo
    RTF               Rich Text Document                                               
    SAV               SAV File                                                         
    SC2MAP            SC2MAP File                                                      
    SC2REPLAY         SC2REPLAY File                                                   
    SC2SAVE           SC2SAVE File                                                     
    SCF               Windows Explorer Command                                         
    SCP               Text Document                                                    
    SCR               Screen saver                                                     
    SCT               Windows Script Component                                         text/scriptlet
    SD2               Sound Designer 2                                                 audio/x-sd2
    SDA                StarOffice 5.0                                           application/vnd.stardivision.draw
    SDC                 StarOffice 5.0                               application/vnd.stardivision.calc
    SDD                StarOffice 5.0                                       application/vnd.stardivision.impress
    SDG                 OpenOffice.org 1.1                                
    SDP               Session Description Protocol                                     application/sdp
    SDS                StarOffice 5.0                                         application/vnd.stardivision.chart
    SDV                 OpenOffice.org 1.1                                
    SDW                 StarOffice 5.0                                application/vnd.stardivision.writer
    SEARCHCONNECTOR-MS  Search Connector Folder                                          application/windows-search-connector+xml
    SEARCH-MS         Saved Search                                                     
    SECSTORE          SECSTORE File                                                    
    SFCACHE           ReadyBoost Cache File                                            
    SGL                 StarOffice 5.0                                application/vnd.stardivision.writer-global
    SHTML             SHTML File                                                       text/html
    SKM               GOM Media file(.skm)                                             
    SKYPE             Skype Content                                                    application/x-skype
    SLUPKG-MS         XrML Digital License Package                                     application/x-ms-license
    SMF                StarOffice 5.0                                           application/vnd.stardivision.math
    SND               AU Format Sound                                                  audio/basic
    SOB                 OpenOffice.org 1.1                                
    SOC                 OpenOffice.org 1.1                                
    SOD                 OpenOffice.org 1.1                                
    SOE                 OpenOffice.org 1.1                                
    SOG                 OpenOffice.org 1.1                                
    SOH                 OpenOffice.org 1.1                                
    SOLITAIRESAVE-MS  .SolitaireSave-ms                                                
    SPC               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    SPIDERSOLITAIRESAVE-MS  .SpiderSolitaireSave-ms                                          
    SPL               Shockwave Flash Object                                           application/futuresplash
    SST               Microsoft Serialized Certificate Store                           application/vnd.ms-pki.certstore
    STC                  OpenOffice.org 1.1                    application/vnd.sun.xml.calc.template
    STD                 OpenOffice.org 1.1                                application/vnd.sun.xml.draw.template
    STI                 OpenOffice.org 1.1                            application/vnd.sun.xml.impress.template
    STL               Certificate Trust List                                           application/vnd.ms-pki.stl
    STW                  OpenOffice.org 1.1                   application/vnd.sun.xml.writer.template
    SVI               GOM Media file(.svi)                                             
    SWF               Shockwave Flash Object                                           application/x-shockwave-flash
    SXC                 OpenOffice.org 1.1                           application/vnd.sun.xml.calc
    SXD                OpenOffice.org 1.1                                       application/vnd.sun.xml.draw
    SXG                 OpenOffice.org 1.1                            application/vnd.sun.xml.writer.global
    SXI                OpenOffice.org 1.1                                   application/vnd.sun.xml.impress
    SXM                OpenOffice.org 1.1                                       application/vnd.sun.xml.math
    SXW                 OpenOffice.org 1.1                            application/vnd.sun.xml.writer
    SYS               System file                                                      
    TAR                WinRAR                                                     
    TAZ                WinRAR                                                     
    TBZ                WinRAR                                                     
    TBZ2               WinRAR                                                     
    TGZ                WinRAR                                                     
    THEME             Windows Theme File                                               
    THEMEPACK         Windows Theme Pack                                               
    THM                 OpenOffice.org 1.1                                
    TIF               TIF File                                                         image/tiff
    TIFF              TIFF File                                                        image/tiff
    TP                GOM Media file(.tp)                                              
    TPS               MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    TRP               GOM Media file(.trp)                                             
    TS                MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    TTC               TrueType Collection Font file                                    
    TTF               TrueType Font file                                               
    TTS               MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TXT               Text Document                                                    text/plain
    UDL               Microsoft Data Link                                              
    UIN               UIN File                                                         application/x-icq
    URL               URL File                                                         
    UU                 WinRAR                                                     
    UUE                WinRAR                                                     
    VBE               VBScript Encoded File                                            
    VBS               VBScript Script File                                             
    VCF               vCard File                                                       text/x-vcard
    VOB               DVD VOB File                                                     video/mpeg
    VOR               STR_REG_VAL_SO50_TEMPLATE_OOO                                    application/vnd.stardivision.writer
    VPK               Source Game Add-on                                               
    VXD               Virtual Device Driver                                            
    WAB               Address Book File                                                
    WAV               Wave Sound                                                       audio/wav
    WAX               Windows Media Audio shortcut                                     audio/x-ms-wax
    WBCAT             Windows Backup Catalog File                                      
    WCX               Workspace Configuration File                                     
    WDP               Windows Media Photo                                              image/vnd.ms-photo
    WEBM              WEBM Video File                                                  video/x-webm
    WEBPNP            Web Point And Print File                                         
    WM                GOM Media file(.wm)                                              video/x-ms-wm
    WMA               Windows Media Audio file                                         audio/x-ms-wma
    WMD               Windows Media Player Download Package                            application/x-ms-wmd
    WMDB              Windows Media Library                                            
    WMF               WMF File                                                         
    WMP               GOM Media file(.wmp)                                             
    WMS               Windows Media Player Skin File                                   
    WMV               Windows Media Video File                                         video/x-ms-wmv
    WMX               GOM Media file(.wmx)                                             video/x-ms-wmx
    WMZ               Windows Media Player Skin Package                                application/x-ms-wmz
    WPL               Windows Media playlist                                           application/vnd.ms-wpl
    WSC               Windows Script Component                                         text/scriptlet
    WSF               Windows Script File                                              
    WSH               Windows Script Host Settings File                                
    WTV               Windows Recorded TV Show                                         
    WTX               Text Document                                                    
    WVX               GOM Media file(.wvx)                                             video/x-ms-wvx
    XAML              Windows Markup File                                              application/xaml+xml
    XBA                 OpenOffice.org 1.1                                
    XBAP              XAML Browser Application                                         application/x-ms-xbap
    XCS                 OpenOffice.org 1.1                                
    XCU                 OpenOffice.org 1.1                                
    XDL                 OpenOffice.org 1.1                                
    XDP                  XML  Adobe Acrobat                         application/vnd.adobe.xdp+xml
    XFDF                Adobe Acrobat                                      application/vnd.adobe.xfdf
    XHT               XHT File                                                         application/xhtml+xml
    XHTML             XHTML File                                                       application/xhtml+xml
    XLS                Microsoft Excel 97-2003                                     
    XLSB               Microsoft Excel                                             
    XLSM               Microsoft Excel                                             
    XLSX               Microsoft Excel                                             
    XLT                Microsoft Excel 97-2003                                   
    XLTM               Microsoft Excel                                           
    XLTX               Microsoft Excel                                           
    XML               XML Document                                                     text/xml
    XPS               XPS Document                                                     application/vnd.ms-xpsdocument
    XRM-MS            XrML Digital License                                             text/xml
    XSL               XSL Stylesheet                                                   text/xml
    XXE                WinRAR                                                     
    Z                  WinRAR                                                     
    ZFSENDTOTARGET    Compressed (zipped) Folder SendTo Target                         
    ZIP                ZIP - WinRAR                                               


--------[    ]--------------------------------------------------------------------------------------

  [ Windows Media Center ]

     :
                                                     Windows Media Center
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               MediaCenter.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Currency.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\ru-RU\gadget.xml

  [   - ]

     :
                                                       -
                                                   ,     .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                      (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                      .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Weather.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                          .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\ru-RU\gadget.xml


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       -
      Winlogon Shell                                    explorer.exe
          (UAC)  
                                   

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  Windows ]------------------------------------------------------------------------------------------

    (Automatic Update)                                                                             
    Security Update for Microsoft .NET Framework 3.5.1, Windows 7, and Windows Server 2008 R2 for x64-based Systems (KB2416471)              07.10.2010
    Update for Windows 7 for x64-based Systems (KB976902)                                         27.10.2010
          Internet Explorer 8  Windows 7      x64 (KB2183461)              12.08.2010
          Internet Explorer 8  Windows 7      x64 (KB2360131)              13.10.2010
          Internet Explorer 8  Windows 7      x64 (KB2416400)              17.12.2010
          Internet Explorer 8  Windows 7      x64 (KB2482017)              09.02.2011
          Internet Explorer 8  Windows 7      x64 (KB2497640)              15.04.2011
          Internet Explorer 8  Windows 7      x64 (KB2530548)              20.06.2011
          Internet Explorer 8  Windows 7      x64 (KB2559049)              11.08.2011
            ActiveX   Windows 7      x64 (KB2508272)              15.04.2011
           ActiveX   Windows 7      x64 (KB2562937)              11.08.2011
      Internet Explorer 8  Windows 7      x64 (KB2398632)              15.09.2010
      Windows 7  64- (x64)  (KB2158563)                            29.09.2010
      Windows 7  64- (x64)  (KB2345886)                            13.10.2010
      Windows 7  64- (x64)  (KB2443685)                            17.12.2010
      Windows 7     64- (x64)  (KB2524375)              24.03.2011
      Windows 7      x64 (KB2506014)                       15.04.2011
      Windows 7      x64 (KB2533552)                       28.05.2011
      Windows 7      x64 (KB2534366)                       12.05.2011
      Windows 7      x64 (KB2552343)                       29.06.2011
       Internet Explorer  Windows 7     64- (x64)  (KB2467659)              17.12.2010
        .NET Framework 3.5.1  64- (x64)  Windows 7  Windows Server 2008 R2 (KB2539634)              11.08.2011
        .NET Framework 4  64- (x64)  Windows XP, Windows Server 2003  2008, Windows Vista, Windows 7, Windows Server 2008 R2 (KB2160841)              05.02.2011
        .NET Framework 4  64- (x64)  Windows XP, Windows Server 2003  2008, Windows Vista, Windows 7, Windows Server 2008 R2 (KB2416472)              16.02.2011
        .NET Framework 4  64- (x64)  Windows XP, Windows Server 2003  2008, Windows Vista, Windows 7, Windows Server 2008 R2 (KB2446708)              15.04.2011
        .NET Framework 4  64- (x64)  Windows XP, Windows Server 2003  2008, Windows Vista, Windows 7, Windows Server 2008 R2 (KB2478663)              15.06.2011
        .NET Framework 4  64- (x64)  Windows XP, Windows Server 2003  2008, Windows Vista, Windows 7, Windows Server 2008 R2 (KB2487367)              11.08.2011
        .NET Framework 4  64- (x64)  Windows XP, Windows Server 2003  2008, Windows Vista, Windows 7, Windows Server 2008 R2 (KB2518870)              15.06.2011
        .NET Framework 4  64- (x64)  Windows XP, Windows Server 2003  2008, Windows Vista, Windows 7, Windows Server 2008 R2 (KB2539636)              11.08.2011
        Windows 7     64- (x64)  (KB2079403)              12.08.2010
        Windows 7     64- (x64)  (KB2160329)              12.08.2010
        Windows 7     64- (x64)  (KB2207566)              13.10.2010
        Windows 7     64- (x64)  (KB2281679)              13.10.2010
        Windows 7     64- (x64)  (KB2286198)              03.08.2010
        Windows 7     64- (x64)  (KB2296011)              13.10.2010
        Windows 7     64- (x64)  (KB2305420)              17.12.2010
        Windows 7     64- (x64)  (KB2347290)              15.09.2010
        Windows 7     64- (x64)  (KB2387149)              13.10.2010
        Windows 7     64- (x64)  (KB2393802)              09.02.2011
        Windows 7     64- (x64)  (KB2419640)              12.01.2011
        Windows 7     64- (x64)  (KB2425227)              09.02.2011
        Windows 7     64- (x64)  (KB2436673)              17.12.2010
        Windows 7     64- (x64)  (KB2475792)              09.02.2011
        Windows 7     64- (x64)  (KB2476490)              18.06.2011
        Windows 7     64- (x64)  (KB2479628)              09.02.2011
        Windows 7     64- (x64)  (KB2479943)              09.03.2011
        Windows 7     64- (x64)  (KB2483614)              09.03.2011
        Windows 7     64- (x64)  (KB2485376)              09.02.2011
        Windows 7     64- (x64)  (KB2491683)              15.04.2011
        Windows 7     64- (x64)  (KB2503658)              15.04.2011
        Windows 7     64- (x64)  (KB2503665)              20.06.2011
        Windows 7     64- (x64)  (KB2506212)              15.04.2011
        Windows 7     64- (x64)  (KB2506223)              15.04.2011
        Windows 7     64- (x64)  (KB2507618)              15.04.2011
        Windows 7     64- (x64)  (KB2507938)              13.07.2011
        Windows 7     64- (x64)  (KB2508429)              15.04.2011
        Windows 7     64- (x64)  (KB2509553)              15.04.2011
        Windows 7     64- (x64)  (KB2510531)              15.04.2011
        Windows 7     64- (x64)  (KB2511455)              15.04.2011
        Windows 7     64- (x64)  (KB2525694)              15.06.2011
        Windows 7     64- (x64)  (KB2532531)              13.07.2011
        Windows 7     64- (x64)  (KB2535512)              15.06.2011
        Windows 7     64- (x64)  (KB2536275)              20.06.2011
        Windows 7     64- (x64)  (KB2536276)              11.08.2011
        Windows 7     64- (x64)  (KB2544893)              17.06.2011
        Windows 7     64- (x64)  (KB2555917)              13.07.2011
        Windows 7     64- (x64)  (KB2556532)              11.08.2011
        Windows 7     64- (x64)  (KB2560656)              11.08.2011
        Windows 7     64- (x64)  (KB2563894)              11.08.2011
        Windows 7     64- (x64)  (KB2567680)              11.08.2011
        Windows 7     64- (x64)  (KB978886)              12.08.2010
        Windows 7     64- (x64)  (KB979687)              13.10.2010
        Windows 7     64- (x64)  (KB980436)              12.08.2010
        Windows 7     64- (x64)  (KB981852)              12.08.2010
        Windows 7     64- (x64)  (KB981957)              13.10.2010
        Windows 7     64- (x64)  (KB982132)              13.10.2010
        Windows 7     64- (x64)  (KB982214)              12.08.2010
        Windows 7     64- (x64)  (KB982799)              12.08.2010
        Windows 7      x64 (KB2296199)              17.12.2010
        Windows 7      x64 (KB2378111)              13.10.2010
        Windows 7      x64 (KB2385678)              17.12.2010
        Windows 7      x64 (KB2423089)              17.12.2010
        Windows 7      x64 (KB2442962)              17.12.2010
        Windows 7      x64 (KB979688)              13.10.2010
        Windows 7      x64 (KB982665)              12.08.2010
         .NET Framework 3.5.1  Windows Server 2008 R2  64- (x64)  (KB2446709)              15.04.2011
         .NET Framework 3.5.1  Windows Server 2008 R2  64- (x64)  (KB2478661)              15.06.2011
         .NET Framework 3.5.1  Windows Server 2008 R2  64- (x64)  (KB2518867)              29.06.2011
         .NET Framework 3.5.1  Windows Server 2008 R2  64- (x64)  (KB983590)              12.08.2010
       MSXML 4.0    2 (SP2)     64- (x64)  (KB973688)              28.03.2011
        Internet Explorer 8  64-  Windows 7 (KB2544521)              20.06.2011
          Microsoft Visual C++ 2008    1 (SP1) (KB2538243)              16.07.2011
          Microsoft Visual C++ 2010 (KB2467173)              03.08.2011
          Microsoft Visual C++ 2010    1 (SP1) (KB2565063)              11.08.2011
         Microsoft XML Core Services (MSXML)4.0   2 (SP2)      x64 (KB954430)              28.03.2011
           64- (x64)  Windows 7 (KB947821) [ 2011 .]              22.06.2011


--------[  ]---------------------------------------------------------------------------------------------------

    NOD32                                                 4.2.71.3                                02.11.2011         ?


--------[  ]--------------------------------------------------------------------------------------------------

     Windows                              6.1.7600.16385  


--------[   ]--------------------------------------------------------------------------------------------

    Microsoft Windows Defender                6.1.7600.16385(win7_rtm.090713-1255)


--------[   ]--------------------------------------------------------------------------------------

     :
                                      ()
                            (UTC+03:00) , , -
                               Last Sunday of October 3:00:00
                                    Last Sunday of March 2:00:00

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   .
         (ISO 4217)                RUB
                                      123456789,00.
                         -123456789,00.

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\Aparratus\AppData\Roaming
    CLASSPATH                 .;C:\Program Files (x86)\QuickTime\QTSystem\QTJava.zip
    CommonProgramFiles(x86)   C:\Program Files (x86)\Common Files
    CommonProgramFiles        C:\Program Files (x86)\Common Files
    CommonProgramW6432        C:\Program Files\Common Files
    COMPUTERNAME              APARRATUS-
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\Aparratus
    LOCALAPPDATA              C:\Users\Aparratus\AppData\Local
    LOGONSERVER               \\APARRATUS-
    NUMBER_OF_PROCESSORS      4
    OS                        Windows_NT
    Path                      C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Samsung\Samsung PC Studio 3;C:\Program Files\Common Files\Microsoft Shared\Windows Live
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_ARCHITEW6432    AMD64
    PROCESSOR_IDENTIFIER      Intel64 Family 6 Model 23 Stepping 7, GenuineIntel
    PROCESSOR_LEVEL           6
    PROCESSOR_REVISION        1707
    ProgramData               C:\ProgramData
    ProgramFiles(x86)         C:\Program Files (x86)
    ProgramFiles              C:\Program Files (x86)
    ProgramW6432              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    QTJAVA                    C:\Program Files (x86)\QuickTime\QTSystem\QTJava.zip
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\APARRA~1\AppData\Local\Temp
    TMP                       C:\Users\APARRA~1\AppData\Local\Temp
    USERDOMAIN                Aparratus-
    USERNAME                  Aparratus
    USERPROFILE               C:\Users\Aparratus
    windir                    C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

    DNA                                       Adjust settings for DNA
    Flash Player                                Flash Player
    Java                                      Java(TM) Control Panel
    QuickTime                                       QuickTime.


--------[  ]-----------------------------------------------------------------------------------------------------

    C:         2          1      ?  ?
    D:            0         0      ?  ?


--------[   ]---------------------------------------------------------------------------------------------

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [MCI Extensions.BAK]
    3g2=MPEGVideo
    3gp=MPEGVideo
    3gp2=MPEGVideo
    3gpp=MPEGVideo
    aac=MPEGVideo
    adt=MPEGVideo
    adts=MPEGVideo
    m2t=MPEGVideo
    m2ts=MPEGVideo
    m2v=MPEGVideo
    m4a=MPEGVideo
    m4v=MPEGVideo
    mod=MPEGVideo
    mov=MPEGVideo
    mp4=MPEGVideo
    mp4v=MPEGVideo
    mts=MPEGVideo
    ts=MPEGVideo
    tts=MPEGVideo

  [ hosts ]

    
    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\Aparratus\AppData\Roaming
    Cache                        C:\Users\Aparratus\AppData\Local\Microsoft\Windows\Temporary Internet Files
    CD Burning                   C:\Users\Aparratus\AppData\Local\Microsoft\Windows\Burn\Burn1
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\Aparratus\Favorites
    Common Files (x86)           C:\Program Files (x86)\Common Files
    Common Files                 C:\Program Files (x86)\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Cookies
    Desktop                      C:\Users\Aparratus\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\Aparratus\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\Aparratus\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\Aparratus\AppData\Local
    My Documents                 C:\Users\Aparratus\Documents
    My Music                     C:\Users\Aparratus\Music
    My Pictures                  C:\Users\Aparratus\Pictures
    My Video                     C:\Users\Aparratus\Videos
    NetHood                      C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\Aparratus
    Program Files (x86)          C:\Program Files (x86)
    Program Files                C:\Program Files (x86)
    Programs                     C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System (x86)                 C:\Windows\SysWOW64
    System                       C:\Windows\system32
    Temp                         C:\Users\APARRA~1\AppData\Local\Temp\
    Templates                    C:\Users\Aparratus\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                         2011-10-26 23:07:50                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-26 23:16:42                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0078bcbc    : 0x13d4     : 0x01cc941ae3aad604    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 6ac4b954-000f-11e1-ba89-0080482e2c3a
                         2011-10-26 23:18:14                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-26 23:50:26                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-27 00:04:52                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : unknown, : 0.0.0.0,   0x00000000   : 0xc0000005   : 0x00000000    : 0x1178     : 0x01cc9421b033c630    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : unknown   : 2561ff54-0016-11e1-ba89-0080482e2c3a
                         2011-10-27 00:05:32                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 00:18:32                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 00:36:38                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 00:48:01                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 01:16:57                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-27 11:10:51                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-27 11:11:08                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 11:22:07                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 12:05:50                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-27 12:13:52                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x00148248    : 0xf48     : 0x01cc94879269212c    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : fc59d69d-007b-11e1-a870-0080482e2c3a
                         2011-10-27 12:36:21                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 12:48:12                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 13:01:12                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-27 13:42:10                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-27 13:42:27                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 13:48:02                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 14:18:22                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-27 14:18:35                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0001c6ec    : 0x1168     : 0x01cc949a14ab440d    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 68fdc72b-008d-11e1-a8c3-0080482e2c3a
                         2011-10-27 14:29:06                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 14:41:54                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-27 14:42:04                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0001c6ec    : 0x13e8     : 0x01cc949d5fb40d9e    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : b0a1fc45-0090-11e1-a8c3-0080482e2c3a
                       2011-10-27 15:39:02                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-27 15:39:18                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 15:48:00                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-27 15:48:14                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0001c6ec    : 0xcbc     : 0x01cc94a69d578499    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : eef47a7f-0099-11e1-b7ca-0080482e2c3a
                         2011-10-27 17:04:26                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-27 17:55:37                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-27 17:55:53                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 18:04:02                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 19:17:22                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 19:32:47                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-27 19:33:24                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0001c6ec    : 0x141c     : 0x01cc94c5f6b883c2    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 63b1d008-00b9-11e1-a436-0080482e2c3a
                         2011-10-27 19:56:00                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 20:06:34                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 20:27:42                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-27 20:28:22                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0001c6ec    : 0x1e70     : 0x01cc94cda33671ac    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 116953fa-00c1-11e1-a436-0080482e2c3a
                         2011-10-27 22:22:39                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 22:49:02                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-27 23:10:52                           Microsoft-Windows-User Profiles Service  1530: C:\Windows\System32\profsvc.dll
                       2011-10-27 23:10:54                           Microsoft-Windows-User Profiles Service  1530: C:\Windows\System32\profsvc.dll
                       2011-10-27 23:25:50                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-27 23:26:08                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-27 23:38:42                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 00:06:39                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 00:16:57                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 01:09:18                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 01:35:47                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-28 12:51:59                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-28 12:52:16                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 13:15:35                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 14:06:32                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 15:04:33                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 15:26:13                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 15:39:08                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 15:52:06                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 16:56:58                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-28 16:57:11                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0001c6ec    : 0x12e8     : 0x01cc957967d65a24    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : bb4382f7-016c-11e1-95ba-0080482e2c3a
                         2011-10-28 17:16:29                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 17:52:12                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 18:39:52                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 19:12:39                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 20:29:35                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 20:51:06                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-28 20:51:18                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0001c6ec    : 0x1dac     : 0x01cc959a1d723b77    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 6ff41677-018d-11e1-95ba-0080482e2c3a
                 101        2011-10-28 21:18:17                                  Application Hang                1002: C:\Windows\System32\wersvc.dll
                         2011-10-28 21:19:37                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-28 23:38:05                                  SideBySide                      75:      "c:\program files (x86)\Creative\audio device selection unicode\CTAudSeu.exe".       "c:\program files (x86)\Creative\audio device selection unicode\CTAudSeu.exe"   2.        requestedPrivileges.  
                         2011-10-28 23:59:29                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 00:35:57                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 00:57:45                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 01:21:27                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 01:57:29                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-29 12:34:13                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-29 12:34:28                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 13:28:06                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 14:34:09                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 14:51:22                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 15:03:26                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-29 15:09:55                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x00c6f8a0    : 0x1af4     : 0x01cc96338dd8c172    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : e981bb72-0226-11e1-941e-0080482e2c3a
                 100        2011-10-29 15:29:22                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0014b220    : 0xb1c     : 0x01cc9633e5b29910    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : a0da6b19-0229-11e1-941e-0080482e2c3a
                         2011-10-29 15:30:06                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-29 15:30:13                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x0001c6ec    : 0x1c6c     : 0x01cc963671139ad8    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : bf9cdc96-0229-11e1-941e-0080482e2c3a
                       2011-10-29 15:38:44                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-29 15:39:02                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 15:46:48                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 101        2011-10-29 16:31:30                                  Application Hang                1002: C:\Windows\System32\wersvc.dll
                         2011-10-29 16:33:08                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 17:03:14                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-29 17:55:15                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-29 17:55:32                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 18:07:57                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-29 18:20:09                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x00c7266a    : 0x1110     : 0x01cc964c7f9ca526    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 7c695886-0241-11e1-a3bc-0080482e2c3a
                         2011-10-29 18:23:23                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 20:38:08                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 21:27:01                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 21:40:23                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 22:17:39                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 22:50:57                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 23:24:20                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-29 23:34:28                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x006b3da0    : 0x1d28     : 0x01cc9679a557cd4b    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 653c82a2-026d-11e1-a3bc-0080482e2c3a
                         2011-10-29 23:35:07                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-29 23:57:59                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 00:41:43                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 01:14:40                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 01:29:50                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 03:05:19                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-30 14:33:36                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-30 14:33:53                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 14:50:21                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 15:03:16                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 15:24:05                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 101        2011-10-30 15:43:06                                  Application Hang                1002: C:\Windows\System32\wersvc.dll
                         2011-10-30 15:43:52                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 17:15:25                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 17:55:29                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 19:00:10                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 19:31:24                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 20:06:03                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 20:19:41                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 21:06:12                                  SideBySide                      75:      "c:\program files (x86)\Creative\audio device selection unicode\CTAudSeu.exe".       "c:\program files (x86)\Creative\audio device selection unicode\CTAudSeu.exe"   2.        requestedPrivileges.  
                         2011-10-30 21:25:23                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 21:58:47                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-30 23:14:21                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-30 23:14:38                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-30 23:26:51                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 00:15:41                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 01:36:04                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-31 11:32:26                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-31 11:32:43                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                       2011-10-31 17:33:40                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-31 17:33:57                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 17:46:24                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-10-31 18:08:02                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : ntdll.dll, : 6.1.7600.16695,   0x4cc7ab86   : 0xc0000005   : 0x00038db9    : 0x1290     : 0x01cc97dc1e1e932c    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\SysWOW64\ntdll.dll   : 2068f87b-03d2-11e1-95b7-0080482e2c3a
                         2011-10-31 18:11:45                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 18:22:21                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 19:43:02                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-10-31 19:43:02                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-31 19:43:20                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 19:48:56                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 22:46:30                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 22:58:02                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-10-31 22:58:02                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-31 22:58:22                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 23:07:54                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 23:26:08                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 23:38:47                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-10-31 23:47:34                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-10-31 23:47:34                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-10-31 23:47:53                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 00:16:10                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-11-01 00:16:47                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x012ac840    : 0x1288     : 0x01cc9812463e651f    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : a3c85b2a-0405-11e1-85e8-0080482e2c3a
                 100        2011-11-01 00:18:00                                  Application Error               1000:   : EACoreServer.exe, : 1.0.0.1,  : 0x4e4f0281    : ntdll.dll, : 6.1.7600.16695,   0x4cc7ab86   : 0xc0000005   : 0x0002e41b    : 0x1210     : 0x01cc98124693b24f    : D:\Games\Origin DL\Battlefield 3\Core\EACoreServer.exe    : C:\Windows\SysWOW64\ntdll.dll   : cf33a57b-0405-11e1-85e8-0080482e2c3a
                         2011-11-01 02:44:05                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 02:44:05                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 02:44:22                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 03:00:25                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-11-01 03:10:10                                  Application Error               1000:   : svchost.exe_SysMain, : 6.1.7600.16385,  : 0x4a5bc3c1    : sysmain.dll, : 6.1.7600.16385,   0x4a5be07e   : 0xc0000005   : 0x000000000000773f    : 0x3d0     : 0x01cc9826f8c356ca    : C:\Windows\System32\svchost.exe    : c:\windows\system32\sysmain.dll   : dc434acd-041d-11e1-9373-0080482e2c3a
                         2011-11-01 03:26:33                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 03:26:33                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 03:26:51                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 03:44:55                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 03:44:55                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 03:45:13                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
               3          2011-11-01 03:46:01                                  Windows Search Service          3036:     <csc://{S-1-5-21-2651418272-3221443202-1083264716-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                 100        2011-11-01 03:55:04                                  Application Error               1000:   : svchost.exe_SysMain, : 6.1.7600.16385,  : 0x4a5bc3c1    : sysmain.dll, : 6.1.7600.16385,   0x4a5be07e   : 0xc0000005   : 0x0000000000054312    : 0x3dc     : 0x01cc982f7670376d    : C:\Windows\System32\svchost.exe    : c:\windows\system32\sysmain.dll   : 21f41c65-0424-11e1-bcf1-0080482e2c3a
                         2011-11-01 04:24:54                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 04:38:37                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 04:42:57                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 04:42:57                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 04:43:18                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-11-01 04:43:43                                  Application Error               1000:   : icq.exe, : 7.0.0.1522,  : 0x4cd03900    : ntdll.dll, : 6.1.7600.16695,   0x4cc7ab86   : 0xc0000005   : 0x0003f977    : 0x910     : 0x01cc9837a196d148    : C:\Program Files (x86)\ICQLite\icq.exe    : C:\Windows\SysWOW64\ntdll.dll   : edf523e8-042a-11e1-99f1-0080482e2c3a
                         2011-11-01 04:50:32                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-11-01 04:53:10                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x00e61a01    : 0xafc     : 0x01cc9838ba33b827    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 3fbfa909-042c-11e1-99f1-0080482e2c3a
                 100        2011-11-01 04:59:39                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x0013420a    : 0xc30     : 0x01cc98390f5dcf03    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : 278c848d-042d-11e1-99f1-0080482e2c3a
                         2011-11-01 05:00:41                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-11-01 05:00:51                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x000dfc6a    : 0xa2c     : 0x01cc983a052dc13d    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 52f7cede-042d-11e1-99f1-0080482e2c3a
                 100        2011-11-01 05:01:57                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x000dfc6a    : 0x2cc     : 0x01cc983a2d13cf3c    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 79be85f8-042d-11e1-99f1-0080482e2c3a
                 100        2011-11-01 05:02:13                                  Application Error               1000:   : AsSysCtrlService.exe, : 0.0.0.0,  : 0x49d43eaf    : unknown, : 0.0.0.0,   0x00000000   : 0xc0000005   : 0x00000000    : 0x634     : 0x01cc983794ea5db3    : C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe    : unknown   : 83c313ae-042d-11e1-99f1-0080482e2c3a
                         2011-11-01 05:12:12                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 05:12:12                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 05:12:27                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 05:23:11                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 15:36:28                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 15:36:28                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 15:36:47                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 15:46:29                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 15:56:33                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 15:56:33                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 15:56:51                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 16:02:15                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 16:45:39                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 16:45:39                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 16:46:00                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 16:53:29                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 17:44:34                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 17:44:34                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 17:44:51                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 17:50:45                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 18:11:49                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 18:11:49                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 18:12:12                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 18:22:33                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 18:34:42                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 18:34:42                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 18:35:00                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 18:40:14                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 18:47:35                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 18:47:35                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 18:47:51                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 18:53:57                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 19:26:01                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 19:26:01                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 19:26:17                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 19:29:22                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 19:41:22                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 19:41:22                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 19:41:44                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 19:48:06                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-11-01 19:51:23                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : unknown, : 0.0.0.0,   0x00000000   : 0xc0000005   : 0x0554fd18    : 0xea8     : 0x01cc98b5f9c964cb    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : unknown   : badf72ab-04a9-11e1-a45d-0080482e2c3a
                 100        2011-11-01 19:52:47                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x000af15b    : 0x44c     : 0x01cc98b6a8eba755    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : ecebc3e5-04a9-11e1-a45d-0080482e2c3a
                 100        2011-11-01 19:53:31                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x000af3ab    : 0x13c     : 0x01cc98b6c2d79f70    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : 06b23213-04aa-11e1-a45d-0080482e2c3a
                 100        2011-11-01 19:54:22                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x000af3ab    : 0xc7c     : 0x01cc98b6e1689ff4    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : 255ef85f-04aa-11e1-a45d-0080482e2c3a
                 100        2011-11-01 19:54:52                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x000af15b    : 0xad4     : 0x01cc98b6f2f70d93    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : 376270a5-04aa-11e1-a45d-0080482e2c3a
                 100        2011-11-01 19:55:23                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x000af3ab    : 0x10fc     : 0x01cc98b7051c8d48    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : 498aaf84-04aa-11e1-a45d-0080482e2c3a
                 100        2011-11-01 19:56:16                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x000af3ab    : 0x1080     : 0x01cc98b72541c847    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : 6960b7ea-04aa-11e1-a45d-0080482e2c3a
                 100        2011-11-01 19:57:45                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x000af3ab    : 0x128c     : 0x01cc98b75a177d23    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : 9e35f795-04aa-11e1-a45d-0080482e2c3a
                 100        2011-11-01 19:58:15                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : nvwgf2um.dll, : 8.17.12.8562,   0x4e992264   : 0xc0000005   : 0x000af3ab    : 0x1104     : 0x01cc98b76ca3fd8b    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\system32\nvwgf2um.dll   : b06f26a4-04aa-11e1-a45d-0080482e2c3a
                         2011-11-01 20:02:20                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 20:02:20                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 20:02:42                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 20:05:41                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 20:28:10                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 20:28:10                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 20:28:27                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 20:32:33                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 20:50:23                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 20:50:23                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 20:50:44                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 20:54:03                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 21:06:49                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 21:06:49                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 21:07:06                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 21:11:50                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 21:30:32                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 21:30:32                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 21:30:50                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 21:36:15                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 21:46:19                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 21:46:19                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 21:46:35                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 21:52:43                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 22:23:24                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 22:40:36                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 22:58:38                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 22:58:38                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 22:58:56                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 23:02:06                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 23:14:29                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 23:14:29                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 23:14:45                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 23:24:16                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-11-01 23:24:27                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : MSVCR90.dll, : 9.0.30729.6161,   0x4dace5b9   : 0xc0000005   : 0x0003aeba    : 0xdbc     : 0x01cc98d431d67a70    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll   : 7ea7575b-04c7-11e1-96d6-0080482e2c3a
                 100        2011-11-01 23:28:35                                  Application Error               1000:   : bf3.exe, : 1.0.0.0,  : 0x4e9d3315    : bf3.exe, : 1.0.0.0,   0x4e9d3315   : 0xc0000005   : 0x000264bb    : 0xaa0     : 0x01cc98d44720c58e    : D:\Games\Origin DL\Battlefield 3\bf3.exe    : D:\Games\Origin DL\Battlefield 3\bf3.exe   : 1249403f-04c8-11e1-96d6-0080482e2c3a
                         2011-11-01 23:31:08                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 23:31:08                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 23:31:20                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 23:35:01                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 23:46:51                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-01 23:46:51                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-01 23:47:09                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-01 23:50:24                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 00:14:32                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 00:14:32                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 00:14:49                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 00:17:39                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 00:29:09                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 00:29:09                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 00:29:26                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 00:38:10                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 01:35:59                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 01:35:59                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 01:36:18                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 01:40:04                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2011-11-02 02:01:04                                  Application Error               1000:   : svchost.exe_SysMain, : 6.1.7600.16385,  : 0x4a5bc3c1    : sysmain.dll, : 6.1.7600.16385,   0x4a5be07e   : 0xc0000005   : 0x00000000000470d3    : 0x3d0     : 0x01cc98e69ec32a3f    : C:\Windows\System32\svchost.exe    : c:\windows\system32\sysmain.dll   : 5f440680-04dd-11e1-ace4-0080482e2c3a
                         2011-11-02 02:12:19                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 02:13:03                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 02:13:03                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 02:13:20                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 02:18:25                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 02:24:08                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 02:24:08                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 02:24:28                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 02:28:50                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 02:32:28                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 02:32:28                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 02:32:44                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 02:56:04                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 02:56:04                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 02:56:23                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 02:57:02                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 02:57:02                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 02:57:24                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 15:24:43                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 15:24:43                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 15:25:03                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 20:23:04                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 20:23:04                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 20:23:26                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 20:34:47                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 20:51:39                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 20:51:39                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 20:52:01                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 21:15:54                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 21:28:38                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2011-11-02 21:39:32                                  Winlogon                        4103: C:\Windows\System32\winlogon.exe
                       2011-11-02 21:39:32                                  Winlogon                        4105: C:\Windows\System32\winlogon.exe
                         2011-11-02 21:39:56                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
      Audit Success   12544      2011-10-26 23:16:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-26 23:16:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 00:04:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 00:04:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-27 01:53:29                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e87      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-27 01:53:39                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-27 11:10:46                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-27 11:10:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2011-10-27 11:10:46                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa684  
      Audit Success   12544      2011-10-27 11:10:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 11:10:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 11:10:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 11:10:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 11:10:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 11:10:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 11:10:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 11:10:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 11:10:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 11:10:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 11:10:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 11:10:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19ccb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 11:10:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19cf3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 11:10:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 11:10:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19ccb    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 11:10:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-27 11:10:50                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-10-27 11:10:51                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-27 11:10:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28590   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 11:11:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 11:11:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 11:12:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 11:12:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 11:13:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x20c    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 11:13:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x5c86e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 11:13:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x5c86e    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 11:13:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 11:13:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 12:13:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 12:13:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-27 13:25:42                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19cf3      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-27 13:25:52                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-27 13:42:06                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa5cd  
      Audit Success   12544      2011-10-27 13:42:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 13:42:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d9e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 13:42:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19dc6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 13:42:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d9e    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-27 13:42:09                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-27 13:42:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 13:42:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-27 13:42:10                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-27 13:42:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x284d5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 13:42:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 13:42:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 13:44:25                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e4    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 13:44:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x8ceb1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 13:44:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x8ceb1    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 13:44:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 13:44:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 14:12:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 14:12:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 14:18:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 14:18:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 14:42:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 14:42:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-27 15:14:37                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19dc6      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-27 15:14:41                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-27 15:38:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-27 15:38:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 15:38:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 15:38:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-27 15:38:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa662  
      Audit Success   12544      2011-10-27 15:38:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 15:38:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 15:38:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 15:38:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 15:38:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 15:38:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 15:38:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 15:38:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 15:39:00                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 15:39:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d78   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 15:39:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19da0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 15:39:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 15:39:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d78    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 15:39:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-27 15:39:01                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-10-27 15:39:02                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-27 15:39:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28899   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 15:39:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 15:39:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 15:41:15                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e4    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 15:41:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x5094b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 15:41:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x5094b    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 15:41:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 15:41:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 15:48:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 15:48:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 16:13:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 16:13:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-27 17:36:32                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19da0      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-27 17:36:35                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-27 17:55:33                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa618  
      Audit Success   12544      2011-10-27 17:55:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 17:55:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 17:55:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 17:55:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 17:55:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 17:55:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e32   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 17:55:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e5a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 17:55:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e32    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-27 17:55:36                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-27 17:55:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 17:55:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-27 17:55:37                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-27 17:55:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x289d7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 17:55:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 17:55:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 17:57:47                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e4    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 17:57:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x46e6e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 17:57:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x46e6e    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 17:57:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 17:57:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 18:14:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 18:14:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 19:33:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 19:33:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 20:28:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 20:28:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-27 23:10:52                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e5a      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-27 23:11:00                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-27 23:25:47                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa635  
      Audit Success   12544      2011-10-27 23:25:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 23:25:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a071   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 23:25:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a099   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 23:25:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a071    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-27 23:25:50                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-10-27 23:25:50                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-27 23:25:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 23:25:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 23:25:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28761   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-27 23:26:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 23:26:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 23:27:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 23:27:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 23:28:02                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e4    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-27 23:28:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6646f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 23:28:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6646f    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-27 23:28:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-27 23:28:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-28 02:46:15                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a099      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-28 02:46:18                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-28 12:51:56                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-28 12:51:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2011-10-28 12:51:56                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa60b  
      Audit Success   12544      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-28 12:51:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 12:51:58                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-28 12:51:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19bed   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-28 12:51:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19c15   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 12:51:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19bed    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-28 12:51:59                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-28 12:51:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 12:51:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-28 12:52:00                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-28 12:52:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28bdf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-28 12:52:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 12:52:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 12:53:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 12:53:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 12:54:10                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e4    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-28 12:54:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x69be2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 12:54:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x69be2    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 12:54:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 12:54:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 16:57:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 16:57:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 18:18:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 18:18:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 19:29:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 19:29:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 20:51:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 20:51:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 21:18:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 21:18:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 23:34:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 23:34:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 23:43:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 23:43:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-28 23:43:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 23:43:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-28 23:44:06                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP      :  0x3e7    :    : 0x11ac    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x32e65e8  
      Audit Success   13568      2011-10-28 23:44:06                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP      :  0x3e7    :    : 0x11ac    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x32e65e8  
      Audit Success   12544      2011-10-28 23:46:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-28 23:46:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-29 02:16:37                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19c15      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-29 02:16:47                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-29 12:34:03                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-29 12:34:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2011-10-29 12:34:03                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9ec2  
      Audit Success   12544      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 12:34:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-29 12:34:13                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-10-29 12:34:13                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-29 12:34:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 12:34:13                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-29 12:34:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c676   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 12:34:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c718   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 12:34:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 12:34:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c676    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 12:34:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2df08   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 12:34:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 12:34:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 12:34:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 12:34:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 12:36:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-29 12:36:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7d34c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 12:36:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7d34c    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 12:36:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 12:36:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 15:09:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:09:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 15:29:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:29:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-29 15:33:03                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c718      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-29 15:33:06                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-29 15:38:41                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-29 15:38:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 15:38:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:38:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-29 15:38:41                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa6fa  
      Audit Success   12544      2011-10-29 15:38:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 15:38:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 15:38:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 15:38:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:38:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 15:38:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 15:38:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 15:38:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 15:38:43                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-29 15:38:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e3b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 15:38:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e63   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:38:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e3b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-29 15:38:44                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-29 15:38:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:38:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-29 15:38:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-29 15:38:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2964d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 15:38:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:38:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 15:39:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:39:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 15:40:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-29 15:40:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7db82   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:40:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7db82    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 15:40:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 15:40:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 16:31:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 16:31:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-29 17:53:07                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19e63      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-29 17:53:13                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-29 17:55:12                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa643  
      Audit Success   12544      2011-10-29 17:55:14                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-29 17:55:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19f9c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 17:55:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19fc4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 17:55:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19f9c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-29 17:55:15                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-10-29 17:55:15                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-29 17:55:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 17:55:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 17:55:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29417   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-29 17:55:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 17:55:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 17:57:29                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-29 17:57:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x57950   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 17:57:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x57950    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 17:57:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 17:57:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 18:20:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 18:20:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 18:40:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 18:40:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-29 23:34:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-29 23:34:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-10-30 00:00:29                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x290   :  C:\Windows\System32\svchost.exe     :  2011-10-29T21:00:19.492811700Z   :  2011-10-29T21:00:29.811398200Z          .    Windows,    ,    .           .  
      Audit Success   12288      2011-10-30 00:00:29                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x290   :  C:\Windows\System32\svchost.exe     :  2011-10-29T21:00:29.832398300Z   :  2011-10-29T21:00:29.832000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2011-10-30 00:00:29                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x290   :  C:\Windows\System32\svchost.exe     :  2011-10-29T21:00:29.843000600Z   :  2011-10-29T21:00:29.843000000Z          .    Windows,    ,    .           .  
      Audit Success   12545      2011-10-30 03:32:33                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19fc4      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-30 03:32:44                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-30 14:33:32                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-30 14:33:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2011-10-30 14:33:32                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa6ae  
      Audit Success   12544      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-30 14:33:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 14:33:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-30 14:33:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a40e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 14:33:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a452   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 14:33:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a40e    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-30 14:33:36                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-10-30 14:33:36                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-30 14:33:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 14:33:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 14:33:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x289af   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 14:33:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 14:33:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 14:35:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 14:35:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 14:35:47                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-30 14:35:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6bc2b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 14:35:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6bc2b    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 14:35:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 14:35:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-10-30 14:37:53                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x174   :  C:\Windows\System32\svchost.exe     :  2011-10-30T11:37:53.381458000Z   :  2011-10-30T11:37:53.381000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2011-10-30 15:43:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 15:43:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 21:11:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 21:11:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 21:11:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 21:11:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 21:22:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-30 21:22:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   7     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1da6807   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 21:22:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   7     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1da683f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2011-10-30 21:22:39                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1da683f     :   7          .           " ".      ,       .  
      Audit Success   12545      2011-10-30 21:22:39                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1da6807     :   7          .           " ".      ,       .  
      Audit Success   12548      2011-10-30 21:22:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1da6807    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-30 22:46:17                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a452      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-30 22:46:26                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-30 23:14:19                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa88d  
      Audit Success   12544      2011-10-30 23:14:20                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-30 23:14:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a0dc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 23:14:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a104   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 23:14:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a0dc    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-30 23:14:21                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-30 23:14:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 23:14:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-30 23:14:22                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-30 23:14:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28556   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-30 23:14:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 23:14:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 23:16:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-30 23:16:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x5b22f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 23:16:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x5b22f    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-30 23:16:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 23:16:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-10-30 23:23:40                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x404   :  C:\Windows\System32\svchost.exe     :  2011-10-30T20:23:40.045888400Z   :  2011-10-30T20:23:40.045000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2011-10-30 23:36:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-30 23:36:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-31 02:46:35                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a104      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-31 02:46:37                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-31 11:32:23                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-31 11:32:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2011-10-31 11:32:23                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa832  
      Audit Success   12544      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 11:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 11:32:25                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 11:32:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a12f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 11:32:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a157   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 11:32:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a12f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-31 11:32:26                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-31 11:32:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 11:32:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-31 11:32:27                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-31 11:32:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x283fe   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 11:32:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 11:32:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 11:33:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 11:33:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 11:34:38                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 11:34:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x67434   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 11:34:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x67434    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 11:34:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 11:34:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-10-31 11:35:44                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x1a8   :  C:\Windows\System32\svchost.exe     :  2011-10-31T08:35:44.164266100Z   :  2011-10-31T08:35:44.164000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2011-10-31 13:06:42                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a12f      :    : 0x584   :  C:\Windows\System32\dllhost.exe     :  2011-10-31T09:06:44.320394900Z   :  2011-10-31T10:06:42.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2011-10-31 13:06:42                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a12f      :    : 0x584   :  C:\Windows\System32\dllhost.exe     :  2011-10-31T10:06:42.000000000Z   :  2011-10-31T10:06:42.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2011-10-31 14:07:00                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a12f      :    : 0xefc   :  C:\Windows\System32\dllhost.exe     :  2011-10-31T10:07:02.451169700Z   :  2011-10-31T11:07:00.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2011-10-31 14:07:00                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a12f      :    : 0xefc   :  C:\Windows\System32\dllhost.exe     :  2011-10-31T11:07:00.000000000Z   :  2011-10-31T11:07:00.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12545      2011-10-31 14:39:09                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a157      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-31 14:39:10                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-31 17:33:37                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-31 17:33:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 17:33:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 17:33:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-31 17:33:37                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa744  
      Audit Success   12544      2011-10-31 17:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 17:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 17:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 17:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 17:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 17:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 17:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 17:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 17:33:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 17:33:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b5f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 17:33:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b87   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 17:33:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 17:33:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b5f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 17:33:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-31 17:33:40                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-10-31 17:33:41                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-31 17:33:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2854f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 17:33:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 17:33:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 17:35:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 17:35:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 17:35:52                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 17:35:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x92e70   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 17:35:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x92e70    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 17:36:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 17:36:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 18:08:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 18:08:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-10-31 19:42:03                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b87      ,   .  ,  ,  .        .  
      Audit Success   103        2011-10-31 19:42:05                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-10-31 19:42:58                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-31 19:42:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2011-10-31 19:42:58                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa829  
      Audit Success   12544      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 19:42:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-31 19:43:01                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-31 19:43:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 19:43:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a350   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 19:43:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a378   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 19:43:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 19:43:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a350    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 19:43:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-31 19:43:03                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-31 19:43:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28648   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 19:43:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 19:43:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 19:45:17                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x210    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 19:45:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x79bcb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 19:45:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x79bcb    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 19:45:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 19:45:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 20:35:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 20:35:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-10-31 22:57:58                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-31 22:57:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 22:57:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 22:57:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-31 22:57:58                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7b9  
      Audit Success   12544      2011-10-31 22:57:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 22:57:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 22:57:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 22:57:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 22:57:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 22:57:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 22:57:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 22:57:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 22:58:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 22:58:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a256   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 22:58:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a27e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 22:58:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a256    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-31 22:58:02                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-31 22:58:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 22:58:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-31 22:58:03                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-31 22:58:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28db0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 22:58:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 22:58:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 23:00:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 23:00:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7e81c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:00:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7e81c    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 23:00:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:00:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 23:35:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:35:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-10-31 23:47:30                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-10-31 23:47:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 23:47:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:47:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-10-31 23:47:30                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7f0  
      Audit Success   12544      2011-10-31 23:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 23:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 23:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 23:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:47:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 23:47:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 23:47:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 23:47:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-10-31 23:47:32                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12292      2011-10-31 23:47:33                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-10-31 23:47:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 23:47:33                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 23:47:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1b4e2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 23:47:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1b50a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:47:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-10-31 23:47:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1b4e2    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-10-31 23:47:34                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-10-31 23:47:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x288d8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-10-31 23:47:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:47:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 23:49:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-10-31 23:49:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6ff48   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:49:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6ff48    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-10-31 23:50:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-10-31 23:50:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 00:16:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 00:16:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 00:36:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 00:36:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-11-01 01:11:29                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1b50a      ,   .  ,  ,  .        .  
      Audit Success   103        2011-11-01 01:11:30                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 02:44:03                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa834  
      Audit Success   12544      2011-11-01 02:44:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 02:44:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a18e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 02:44:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a1b6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 02:44:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a18e    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 02:44:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-11-01 02:44:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 02:44:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 02:44:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 02:44:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2877d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 02:44:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 02:44:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 02:44:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 02:44:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 02:46:16                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 02:46:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x795ee   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 02:46:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x795ee    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 02:46:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 02:46:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:10:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:10:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:10:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:10:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 03:26:30                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 03:26:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:26:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:26:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 03:26:30                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaed7  
      Audit Success   12544      2011-11-01 03:26:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:26:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:26:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:26:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:26:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 03:26:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 03:26:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 03:26:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:26:32                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 03:26:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b8d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:26:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19be4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:26:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b8d    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 03:26:33                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-11-01 03:26:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:26:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 03:26:34                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 03:26:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x291f4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:26:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:26:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:28:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 03:28:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x92293   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:28:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x92293    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:29:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:29:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 03:44:49                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 03:44:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2011-11-01 03:44:49                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa81e  
      Audit Success   12544      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 03:44:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 03:44:53                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 03:44:53                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 03:44:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1968a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:44:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x196fc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:44:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1968a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:44:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:44:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 03:44:55                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 03:44:56                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 03:45:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28d89   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 03:45:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:45:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:46:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:46:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:46:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:46:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:47:07                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 03:47:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9a1aa   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:47:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9a1aa    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:47:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:47:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:55:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:55:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 03:55:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 03:55:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 04:23:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 04:23:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:23:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 04:23:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 04:23:39                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP      :  0x3e7    :    : 0x260    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1e26e0  
      Audit Success   13568      2011-11-01 04:23:39                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP      :  0x3e7    :    : 0x260    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1e26e0  
      Audit Success   12288      2011-11-01 04:42:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 04:42:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 04:42:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 04:42:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:42:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 04:42:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 04:42:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb103  
      Audit Success   12544      2011-11-01 04:42:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 04:42:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 04:42:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:42:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 04:42:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 04:42:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 04:42:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 04:42:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19fef   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 04:42:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a04b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:42:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19fef    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 04:42:56                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 04:42:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:42:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 04:42:57                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 04:42:57                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 04:43:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28a64   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 04:43:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:43:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 04:43:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:43:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 04:45:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 04:45:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xab25f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:45:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xab25f    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 04:45:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:45:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 04:46:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:46:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 04:53:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:53:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 04:59:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 04:59:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-11-01 05:02:12                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a04b      ,   .  ,  ,  .        .  
      Audit Success   103        2011-11-01 05:02:13                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 05:12:05                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa873  
      Audit Success   12292      2011-11-01 05:12:07                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 05:12:07                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 05:12:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 05:12:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 05:12:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 05:12:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1db20   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 05:12:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1db37   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 05:12:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1db20    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 05:12:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x21c08   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 05:12:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 05:12:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 05:14:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 05:14:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x62e7c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 05:14:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x62e7c    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 05:14:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 05:14:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 15:36:23                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 15:36:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:36:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:36:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 15:36:23                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa824  
      Audit Success   12544      2011-11-01 15:36:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:36:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:36:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:36:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:36:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 15:36:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 15:36:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 15:36:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 15:36:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 15:36:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1b538   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:36:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1b560   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:36:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1b538    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 15:36:28                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-11-01 15:36:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:36:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 15:36:29                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   101        2011-11-01 15:36:30                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 15:36:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2a7a5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:36:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:36:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 15:37:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:37:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 15:38:40                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 15:38:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7afb1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:38:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7afb1    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 15:38:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:38:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 15:56:30                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa87c  
      Audit Success   12544      2011-11-01 15:56:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:56:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:56:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 15:56:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 15:56:32                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 15:56:32                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 15:56:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a35b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:56:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a383   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:56:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a35b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 15:56:33                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-11-01 15:56:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:56:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 15:56:34                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 15:56:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28619   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 15:56:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:56:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 15:58:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 15:58:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6858f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:58:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6858f    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 15:59:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 15:59:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 16:37:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 16:37:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 16:45:36                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 16:45:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 16:45:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 16:45:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 16:45:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 16:45:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 16:45:36                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa89b  
      Audit Success   12544      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1925c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x192d1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 16:45:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1925c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 16:45:39                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 16:45:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 16:45:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 16:45:40                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 16:45:41                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 16:45:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2c0c3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 16:45:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 16:45:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 16:45:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 16:45:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 16:47:50                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 16:47:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x68b4c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 16:47:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x68b4c    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 16:47:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 16:47:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 17:37:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 17:37:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 17:44:31                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa890  
      Audit Success   12544      2011-11-01 17:44:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 17:44:32                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 17:44:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a42f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 17:44:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a482   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 17:44:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 17:44:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a42f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 17:44:33                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12292      2011-11-01 17:44:34                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 17:44:34                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 17:44:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27a4f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 17:44:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 17:44:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 17:46:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 17:46:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6d11d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 17:46:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6d11d    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 17:47:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 17:47:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 18:11:48                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa939  
      Audit Success   101        2011-11-01 18:11:49                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 18:11:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 18:11:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a108   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:11:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a130   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:11:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:11:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a108    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:11:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 18:11:50                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 18:11:51                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 18:11:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27826   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:12:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:12:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:12:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:12:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:14:09                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 18:14:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa32de   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:14:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa32de    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:14:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:14:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:14:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:14:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 18:34:40                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa886  
      Audit Success   12544      2011-11-01 18:34:41                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 18:34:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19a22   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:34:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19a50   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:34:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19a22    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 18:34:43                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 18:34:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:34:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 18:34:44                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 18:34:44                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 18:34:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2d1ff   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:34:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:34:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:37:02                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 18:37:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6f72f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:37:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6f72f    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:37:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:37:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:37:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:37:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 18:47:27                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa956  
      Audit Success   12544      2011-11-01 18:47:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:47:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:47:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 18:47:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 18:47:29                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 18:47:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 18:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1962f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19657   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:47:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1962f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:47:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:47:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 18:47:33                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 18:47:35                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 18:47:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29856   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 18:47:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:47:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:48:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:48:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:49:50                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 18:49:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7f47f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:49:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7f47f    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 18:50:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 18:50:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 19:25:56                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa8cf  
      Audit Success   101        2011-11-01 19:25:57                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12292      2011-11-01 19:25:59                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 19:25:59                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 19:25:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 19:25:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a3c7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:25:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a3ef   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:25:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:25:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a3c7    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 19:25:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 19:26:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2907f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:26:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:26:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 19:28:11                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 19:28:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9f87b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:28:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9f87b    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 19:28:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:28:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 19:41:19                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 19:41:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:41:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:41:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 19:41:19                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa8b0  
      Audit Success   12544      2011-11-01 19:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 19:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 19:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 19:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 19:41:21                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 19:41:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 19:41:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19163   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:41:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1918b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:41:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19163    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 19:41:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:41:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 19:41:23                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 19:41:23                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 19:41:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2d551   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 19:41:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:41:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 19:41:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:41:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 19:43:33                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 19:43:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7d8dd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:43:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7d8dd    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 19:43:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:43:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 19:51:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 19:51:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-11-01 19:58:32                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1918b      ,   .  ,  ,  .        .  
      Audit Success   103        2011-11-01 19:58:34                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-11-01 20:02:16                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 20:02:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:02:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:02:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 20:02:16                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7eb  
      Audit Success   12544      2011-11-01 20:02:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:02:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:02:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:02:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:02:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:02:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:02:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:02:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:02:18                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 20:02:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19f0b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:02:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19f33   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:02:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:02:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19f0b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:02:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 20:02:19                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 20:02:25                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 20:02:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28597   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:02:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:02:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:03:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:03:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:04:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 20:04:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9ef0e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:04:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9ef0e    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:04:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:04:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-11-01 20:09:44                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19f33      ,   .  ,  ,  .        .  
      Audit Success   103        2011-11-01 20:09:45                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-11-01 20:28:07                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 20:28:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:28:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:28:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 20:28:07                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa8b2  
      Audit Success   12544      2011-11-01 20:28:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:28:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:28:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:28:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:28:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:28:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:28:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:28:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:28:10                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 20:28:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19f78   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:28:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19fc5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:28:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:28:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19f78    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:28:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 20:28:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 20:28:11                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 20:28:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x275e0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:28:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:28:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:30:26                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 20:30:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7c5ae   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:30:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7c5ae    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:30:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:30:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 20:50:20                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7d1  
      Audit Success   12544      2011-11-01 20:50:22                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 20:50:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x18f63   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:50:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x18f8b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:50:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x18f63    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 20:50:24                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 20:50:24                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 20:50:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:50:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:50:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28a88   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 20:50:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:50:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:50:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:50:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:52:33                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 20:52:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xb1496   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:52:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xb1496    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 20:52:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 20:52:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 21:06:45                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 21:06:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:06:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:06:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 21:06:45                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa783  
      Audit Success   12544      2011-11-01 21:06:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:06:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:06:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:06:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:06:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:06:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:06:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:06:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:06:47                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 21:06:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d33   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:06:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d62   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:06:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d33    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 21:06:48                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 21:06:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:06:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 21:06:49                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 21:06:50                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 21:06:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28739   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:06:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:06:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:09:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 21:09:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6a4e1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:09:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6a4e1    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:09:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:09:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 21:30:27                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa83d  
      Audit Success   12544      2011-11-01 21:30:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:30:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:30:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:30:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 21:30:29                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 21:30:30                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 21:30:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b7a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:30:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19bfd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:30:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:30:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b7a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:30:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 21:30:31                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 21:30:31                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 21:30:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28946   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:30:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:30:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:32:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 21:32:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x69ccb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:32:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x69ccb    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:33:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:33:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 21:46:15                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa85c  
      Audit Success   101        2011-11-01 21:46:17                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 21:46:17                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 21:46:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19a3a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:46:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19a62   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:46:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19a3a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:46:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:46:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 21:46:19                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 21:46:20                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 21:46:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x285dd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 21:46:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:46:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:48:28                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 21:48:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x98831   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:48:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x98831    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:48:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:48:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 21:51:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 21:51:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 22:58:34                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa851  
      Audit Success   101        2011-11-01 22:58:36                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 22:58:36                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 22:58:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x194ad   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 22:58:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x194d5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 22:58:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x194ad    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 22:58:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 22:58:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 22:58:38                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 22:58:39                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 22:58:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27fca   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 22:58:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 22:58:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:00:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 23:00:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9d987   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:00:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9d987    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:00:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:00:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 23:14:25                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 23:14:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:14:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:14:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 23:14:25                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa85d  
      Audit Success   12544      2011-11-01 23:14:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:14:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:14:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:14:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:14:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:14:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:14:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:14:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 23:14:27                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 23:14:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 23:14:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b56   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:14:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19be3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:14:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19b56    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:14:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:14:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 23:14:29                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 23:14:30                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 23:14:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28e19   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:14:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:14:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:16:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 23:16:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9bb39   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:16:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9bb39    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:16:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:16:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:24:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:24:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:28:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:28:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 23:30:58                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb174  
      Audit Success   12544      2011-11-01 23:31:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 23:31:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a288   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:31:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a2d7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:31:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a288    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 23:31:04                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 23:31:04                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 23:31:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:31:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:31:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2081d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   101        2011-11-01 23:31:12                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 23:31:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:31:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:32:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:32:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:33:25                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 23:33:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9a727   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:33:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x9a727    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:33:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:33:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-01 23:46:47                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-01 23:46:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:46:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:46:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-01 23:46:47                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa893  
      Audit Success   12544      2011-11-01 23:46:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:46:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:46:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:46:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:46:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:46:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:46:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:46:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-01 23:46:50                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-01 23:46:50                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 23:46:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19ba3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:46:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19bea   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:46:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:46:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19ba3    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-01 23:46:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-01 23:46:51                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-01 23:46:52                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-01 23:46:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29155   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-01 23:47:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:47:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:49:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-01 23:49:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa2fd1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:49:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa2fd1    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:49:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:49:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-01 23:52:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-01 23:52:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 00:14:28                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 00:14:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:14:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:14:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 00:14:28                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa838  
      Audit Success   12544      2011-11-02 00:14:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:14:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:14:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:14:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:14:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 00:14:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 00:14:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 00:14:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-02 00:14:30                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-02 00:14:30                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 00:14:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19625   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:14:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19656   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:14:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19625    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 00:14:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:14:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 00:14:32                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 00:14:32                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 00:14:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2859e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:14:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:14:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 00:16:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 00:16:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa9326   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:16:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa9326    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 00:16:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:16:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 00:29:05                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 00:29:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2011-11-02 00:29:05                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7f1  
      Audit Success   12544      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 00:29:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-02 00:29:08                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-02 00:29:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 00:29:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1969c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:29:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x196f3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:29:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:29:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1969c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 00:29:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 00:29:09                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 00:29:10                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 00:29:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28309   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 00:29:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:29:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 00:31:23                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 00:31:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x85279   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:31:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x85279    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 00:31:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:31:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 00:52:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 00:52:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-11-02 01:13:01                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x196f3      ,   .  ,  ,  .        .  
      Audit Success   103        2011-11-02 01:13:02                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 01:35:55                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7a7  
      Audit Success   12544      2011-11-02 01:35:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 01:35:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 01:35:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 01:35:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 01:35:58                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 01:35:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a2eb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 01:35:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a31a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 01:35:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1a2eb    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 01:35:59                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2011-11-02 01:35:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 01:35:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 01:36:00                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 01:36:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28a73   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 01:36:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 01:36:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 01:38:09                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 01:38:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa3559   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 01:38:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa3559    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 01:38:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 01:38:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 01:53:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 01:53:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:01:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:01:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:01:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:01:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 02:09:34                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1997f      :    : 0xf98   :  C:\Windows\System32\dllhost.exe     :  2011-11-02T00:09:35.996003800Z   :  2011-11-01T23:09:34.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2011-11-02 02:09:34                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1997f      :    : 0xf98   :  C:\Windows\System32\dllhost.exe     :  2011-11-01T23:09:34.000000000Z   :  2011-11-01T23:09:34.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2011-11-02 02:12:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 02:12:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:12:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:12:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 02:12:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa88b  
      Audit Success   12544      2011-11-02 02:13:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:13:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:13:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:13:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:13:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:13:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:13:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:13:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:13:02                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:13:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1991c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:13:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1996d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:13:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:13:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1991c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:13:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 02:13:03                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 02:13:04                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 02:13:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27ec3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:13:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:13:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:15:13                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:15:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xb08fd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:15:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xb08fd    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:15:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:15:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 02:24:03                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 02:24:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:24:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:24:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 02:24:03                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa84b  
      Audit Success   12544      2011-11-02 02:24:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:24:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:24:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:24:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:24:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:24:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:24:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:24:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-02 02:24:06                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-02 02:24:06                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:24:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1987d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:24:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x198d9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:24:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1987d    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:24:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:24:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 02:24:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 02:24:09                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 02:24:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x281e1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:24:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:24:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:26:23                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:26:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7eee5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:26:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7eee5    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:26:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:26:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:26:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:26:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 02:32:24                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa8ce  
      Audit Success   101        2011-11-02 02:32:26                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-02 02:32:26                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:32:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19864   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:32:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x198af   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:32:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19864    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:32:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:32:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 02:32:28                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 02:32:29                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 02:32:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28c64   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:32:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:32:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:32:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:32:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:34:38                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:34:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa6b17   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:34:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0xa6b17    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:34:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:34:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 02:56:01                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa8a8  
      Audit Success   12544      2011-11-02 02:56:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-02 02:56:03                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-02 02:56:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:56:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1997f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x199a7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1997f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:56:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 02:56:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 02:56:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 02:56:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x288fb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:56:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 02:56:47                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 02:56:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 02:56:48                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb096  
      Audit Success   12544      2011-11-02 02:56:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:56:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:56:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 02:56:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:56:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:56:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x198a0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 02:56:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x198d7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:56:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x198a0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:57:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:57:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 02:57:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 02:57:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 02:57:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x22c29   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   101        2011-11-02 02:57:17                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-02 02:57:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:57:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:58:15                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:58:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7d828   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:58:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7d828    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:58:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:58:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:59:22                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x21c    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 02:59:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6d6b4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:59:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6d6b4    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 02:59:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 02:59:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 03:10:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 03:10:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 03:34:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 03:34:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 03:34:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 03:34:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 03:34:06                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP      :  0x3e7    :    : 0xd7c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x162e51  
      Audit Success   13568      2011-11-02 03:34:06                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP      :  0x3e7    :    : 0xd7c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x162e51  
      Audit Success   12544      2011-11-02 04:08:51                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 04:08:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   7     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1945c4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 04:08:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   7     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1945d2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2011-11-02 04:08:51                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1945d2     :   7          .           " ".      ,       .  
      Audit Success   12545      2011-11-02 04:08:51                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1945c4     :   7          .           " ".      ,       .  
      Audit Success   12548      2011-11-02 04:08:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1945c4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 05:05:24                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 05:05:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   7     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c11ca   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 05:05:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   7     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c11d8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 05:05:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c11ca    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-11-02 05:05:26                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c11d8     :   7          .           " ".      ,       .  
      Audit Success   12545      2011-11-02 05:05:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1c11ca     :   7          .           " ".      ,       .  
      Audit Success   12545      2011-11-02 05:46:48                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x198d7      ,   .  ,  ,  .        .  
      Audit Success   103        2011-11-02 05:46:49                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 15:24:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa795  
      Audit Success   12544      2011-11-02 15:24:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x288    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 15:24:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19bf4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 15:24:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19c48   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 15:24:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19bf4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 15:24:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 15:24:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 15:24:44                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 15:24:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 15:24:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27fd9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 15:24:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 15:24:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 15:25:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 15:25:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 15:26:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e4    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 15:26:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7cbe4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 15:26:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x7cbe4    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 15:26:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 15:26:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2011-11-02 15:45:26                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19c48      ,   .  ,  ,  .        .  
      Audit Success   103        2011-11-02 15:45:27                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 20:22:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7a1  
      Audit Success   12544      2011-11-02 20:23:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 20:23:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d93   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:23:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19dbb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:23:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19d93    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:23:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:23:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 20:23:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 20:23:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 20:23:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2819c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:23:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:23:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:23:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:23:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:25:16                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e4    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 20:25:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x8fa39   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:25:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x8fa39    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:25:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:25:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 20:51:33                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 20:51:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:51:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:51:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 20:51:33                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa829  
      Audit Success   12544      2011-11-02 20:51:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:51:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:51:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 20:51:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:51:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:51:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:51:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 20:51:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-02 20:51:37                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-02 20:51:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 20:51:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1986b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:51:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x198c7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:51:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x1986b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:51:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:51:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 20:51:39                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 20:51:41                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 20:51:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x289ba   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 20:51:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:51:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:53:51                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e0    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 20:53:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6803a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:53:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x6803a    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:53:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:53:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 20:59:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 20:59:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 21:24:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 21:24:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2011-11-02 21:39:27                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2011-11-02 21:39:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 21:39:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 21:39:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2011-11-02 21:39:27                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa913  
      Audit Success   12544      2011-11-02 21:39:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 21:39:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 21:39:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 21:39:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 21:39:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 21:39:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 21:39:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 21:39:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2011-11-02 21:39:30                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2011-11-02 21:39:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  Aparratus     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 21:39:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x199af   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 21:39:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x19a00   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : APARRATUS-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 21:39:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 21:39:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1000     :  Aparratus     :  Aparratus-    :  0x199af    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2011-11-02 21:39:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2011-11-02 21:39:33                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2011-11-02 21:39:34                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2011-11-02 21:39:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x289ab   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2011-11-02 21:39:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 21:39:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 21:41:44                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  Aparratus-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e0    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2011-11-02 21:41:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x65dcc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     : APARRATUS-     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 21:41:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2651418272-3221443202-1083264716-1009     :  UpdatusUser     :  Aparratus-    :  0x65dcc    :  SeAssignPrimaryTokenPrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 21:41:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 21:41:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 21:58:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 21:58:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 22:25:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 22:25:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2011-11-02 23:03:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  APARRATUS-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2011-11-02 23:03:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
                          2011-10-26 23:56:31  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     counter.yadro.ru        DNS.  
                            2011-10-27 11:10:40                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-27 11:11:00                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-10-27 13:42:00                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-27 13:42:20                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-10-27 15:38:52                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-27 15:39:11                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-10-27 17:55:27                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-27 17:55:46                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-10-27 21:45:41  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     aus3.mozilla.org        DNS.  
                            2011-10-27 23:25:41                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-27 23:26:00                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-10-28 12:51:50                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-28 12:52:09                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                    2          2011-10-28 19:30:01                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-10-28 19:30:01                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-10-28 19:30:01                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-10-28 19:30:01                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                          2011-10-29 00:55:28  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     www.adobe.com        DNS.  
                            2011-10-29 12:33:57                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-29 12:34:21                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-10-29 13:28:39  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     web.dm.origin.com        DNS.  
                            2011-10-29 15:38:35                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-29 15:38:55                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-10-29 17:38:28  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     dns.msftncsi.com        DNS.  
                            2011-10-29 17:55:06                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-29 17:55:25                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-10-29 17:55:40  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     teredo.ipv6.microsoft.com        DNS.  
                          2011-10-30 03:05:29  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     344786-gosprapp170.ea.com        DNS.  
                            2011-10-30 14:33:26                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-30 14:33:46                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-10-30 21:28:51  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     img17.imageshack.us        DNS.  
                            2011-10-30 23:14:12                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-30 23:14:31                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-10-31 00:18:15  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     time.infodesign.ru        DNS.  
                            2011-10-31 11:32:16                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-31 11:32:37                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-10-31 17:33:30                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-31 17:33:50                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-10-31 19:19:37  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     rom-by.com        DNS.  
                            2011-10-31 19:42:51                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-31 19:43:13                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-10-31 19:44:27  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     battlefieldo.com        DNS.  
                            2011-10-31 22:57:52                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-31 22:57:59                                  EventLog                        6008:      22:53:51  ?31.?10.?2011  .  
                            2011-10-31 22:58:15                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-10-31 23:47:24                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-10-31 23:47:31                                  EventLog                        6008:      23:43:52  ?31.?10.?2011  .  
                            2011-10-31 23:47:45                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 02:43:55                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 02:44:16                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-11-01 02:55:14  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     counter.rambler.ru        DNS.  
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7034: C:\Windows\system32\services.exe
                            2011-11-01 03:10:12                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:26:24                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 03:26:31                                  EventLog                        6008:      3:14:56  ?01.?11.?2011  .  
                            2011-11-01 03:26:45                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-11-01 03:27:45  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     static.cdn.ea.com        DNS.  
                            2011-11-01 03:44:43                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 03:44:50                                  EventLog                        6008:      3:34:25  ?01.?11.?2011  .  
                            2011-11-01 03:44:53                                  BugCheck                        
                            2011-11-01 03:45:06                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7034: C:\Windows\system32\services.exe
                            2011-11-01 03:55:07                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                          2011-11-01 04:32:12                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                          2011-11-01 04:32:14                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                          2011-11-01 04:32:15                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                          2011-11-01 04:32:17                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                          2011-11-01 04:32:43  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     akamai.cdn.ea.com        DNS.  
                            2011-11-01 04:42:44                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 04:42:52                                  EventLog                        6008:      4:41:43  ?01.?11.?2011  .  
                            2011-11-01 04:42:54                                  BugCheck                        
                            2011-11-01 04:43:07                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-11-01 04:50:40  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     gosredirector.ea.com        DNS.  
                            2011-11-01 05:11:58                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 05:12:18                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 15:36:17                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 15:36:24                                  EventLog                        6008:      5:29:58  ?01.?11.?2011  .  
                            2011-11-01 15:36:39                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 15:56:23                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 15:56:31                                  EventLog                        6008:      15:52:17  ?01.?11.?2011  .  
                            2011-11-01 15:56:43                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 16:45:30                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 16:45:37                                  EventLog                        6008:      16:40:23  ?01.?11.?2011  .  
                            2011-11-01 16:45:50                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 17:44:24                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 17:44:31                                  EventLog                        6008:      17:39:30  ?01.?11.?2011  .  
                            2011-11-01 17:44:43                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 18:11:42                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 18:11:48                                  EventLog                        6008:      18:08:24  ?01.?11.?2011  .  
                            2011-11-01 18:12:01                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 18:34:33                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 18:34:40                                  EventLog                        6008:      18:30:42  ?01.?11.?2011  .  
                            2011-11-01 18:34:53                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 18:47:20                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 18:47:28                                  EventLog                        6008:      18:44:33  ?01.?11.?2011  .  
                            2011-11-01 18:47:30                                  BugCheck                        
                            2011-11-01 18:47:42                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 19:25:49                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 19:25:56                                  EventLog                        6008:      19:22:20  ?01.?11.?2011  .  
                            2011-11-01 19:26:10                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 19:41:13                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 19:41:20                                  EventLog                        6008:      19:36:49  ?01.?11.?2011  .  
                            2011-11-01 19:41:32                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 19:56:34                           Ntfs                            131: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 19:56:34                           Ntfs                            131: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 19:56:34                           Ntfs                            131: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 19:56:34                           Ntfs                            131: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:36                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                          2011-11-01 19:56:36                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                          2011-11-01 19:56:36                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 19:56:40                           Ntfs                            131: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 19:56:40                           Ntfs                            131: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 19:56:40                           Ntfs                            131: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 19:56:40                           Ntfs                            131: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:40                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:40                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:40                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:40                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:40                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:40                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:40                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:40                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                          2011-11-01 19:56:41                           Ntfs                            132: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:42                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:42                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:42                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:42                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:42                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:42                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:42                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:48                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:48                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:48                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:48                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:48                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:48                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 19:56:48                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 20:02:09                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 20:02:34                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 20:28:00                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 20:28:20                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 20:50:13                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 20:50:20                                  EventLog                        6008:      20:39:00  ?01.?11.?2011  .  
                            2011-11-01 20:50:32                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 21:06:39                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 21:06:46                                  EventLog                        6008:      21:02:13  ?01.?11.?2011  .  
                            2011-11-01 21:06:59                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 21:30:20                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 21:30:28                                  EventLog                        6008:      21:27:39  ?01.?11.?2011  .  
                            2011-11-01 21:30:43                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 21:46:08                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 21:46:15                                  EventLog                        6008:      21:42:20  ?01.?11.?2011  .  
                            2011-11-01 21:46:28                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 22:58:27                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 22:58:34                                  EventLog                        6008:      22:53:08  ?01.?11.?2011  .  
                            2011-11-01 22:58:47                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 23:14:18                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 23:14:26                                  EventLog                        6008:      23:09:27  ?01.?11.?2011  .  
                            2011-11-01 23:14:38                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-01 23:30:52                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 23:30:58                                  EventLog                        6008:      23:29:19  ?01.?11.?2011  .  
                            2011-11-01 23:31:02                                  BugCheck                        
                            2011-11-01 23:31:14                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                          2011-11-01 23:38:37                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-01 23:46:41                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-01 23:46:48                                  EventLog                        6008:      23:42:52  ?01.?11.?2011  .  
                            2011-11-01 23:47:00                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:09                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2011-11-01 23:47:10                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-02 00:14:21                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 00:14:29                                  EventLog                        6008:      23:57:41  ?01.?11.?2011  .  
                            2011-11-02 00:14:41                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 00:28:58                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 00:29:06                                  EventLog                        6008:      0:23:21  ?02.?11.?2011  .  
                            2011-11-02 00:29:18                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 01:35:48                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 01:36:08                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7034: C:\Windows\system32\services.exe
                            2011-11-02 02:01:05                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2011-11-02 02:12:52                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 02:13:00                                  EventLog                        6008:      2:08:48  ?02.?11.?2011  .  
                          2011-11-02 02:13:01  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     counter.yadro.ru        DNS.  
                            2011-11-02 02:13:12                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 02:23:56                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 02:24:04                                  EventLog                        6008:      2:22:52  ?02.?11.?2011  .  
                            2011-11-02 02:24:05                                  BugCheck                        
                            2011-11-02 02:24:17                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 02:32:17                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 02:32:24                                  EventLog                        6008:      2:30:52  ?02.?11.?2011  .  
                            2011-11-02 02:32:26                                  BugCheck                        
                            2011-11-02 02:32:37                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 02:32:38  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   18:    .     :     : 3   : 10   : 0           .  
                            2011-11-02 02:32:38  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   18:    .     :     : 3   : 10   : 0           .  
                            2011-11-02 02:32:38  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   18:    .     :     : 3   : 10   : 1           .  
                            2011-11-02 02:32:38  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   18:    .     :     : 3   : 10   : 2           .  
                            2011-11-02 02:32:38  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   18:    .     :     : 3   : 10   : 2           .  
                            2011-11-02 02:32:38  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   18:    .     :     : 3   : 10   : 3           .  
                          2011-11-02 02:34:23  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     jobs.ea.com        DNS.  
                            2011-11-02 02:43:02                                  volsnap                         36: 
                          2011-11-02 02:50:02                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                            2011-11-02 02:55:54                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 02:56:01                                  EventLog                        6008:      2:45:56  ?02.?11.?2011  .  
                            2011-11-02 02:56:14                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 02:56:34                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 02:56:53                                  EventLog                        6008:      2:55:17  ?02.?11.?2011  .  
                            2011-11-02 02:56:55                                  BugCheck                        
                            2011-11-02 02:57:18                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 04:08:45                                  DCOM                            
                          2011-11-02 05:05:30  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     teredo.ipv6.microsoft.com        DNS.  
                            2011-11-02 15:24:31                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 15:24:53                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 20:22:52                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 20:23:14                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 20:51:27                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 20:51:35                                  EventLog                        6008:      20:47:52  ?02.?11.?2011  .  
                            2011-11-02 20:51:50                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 21:39:20                                  Application Popup               1060:  \SystemRoot\SysWow64\Drivers\StarOpen.SYS  -    .         .  
                            2011-11-02 21:39:28                                  EventLog                        6008:      21:35:27  ?02.?11.?2011  .  
                            2011-11-02 21:39:43                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2011-11-02 21:59:55                                  DCOM                            


--------[   ]-------------------------------------------------------------------------------------------------------

      :
      Borland Database Engine                           -
      Borland InterBase Client                          -
      Easysoft ODBC-InterBase 6                         -
      Easysoft ODBC-InterBase 7                         -
      Firebird Client                                   -
      Jet Engine                                        4.00.9756.0
      MDAC                                              6.1.7600.16385 (win7_rtm.090713-1255)
      ODBC                                              6.1.7600.16688 (win7_gdr.101015-1505)
      MySQL Connector/ODBC                              -
      Oracle Client                                     -
      PsqlODBC                                          -
      Sybase ASE ODBC                                   -

     :
      Borland InterBase Server                          -
      Firebird Server                                   -
      Microsoft SQL Server                              -
      Microsoft SQL Server Compact Edition              -
      Microsoft SQL Server Express Edition              -
      MySQL Server                                      -
      Oracle Server                                     -
      PostgreSQL Server                                 -
      Sybase SQL Server                                 -


--------[  ODBC ]-----------------------------------------------------------------------------------------------

    Driver da Microsoft para arquivos texto (*.txt; *.csv)      odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Driver do Microsoft Access (*.mdb)                          odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.mdb
    Driver do Microsoft dBase (*.dbf)                           odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.dbf,*.ndx,*.mdx
    Driver do Microsoft Excel(*.xls)                            odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.xls
    Driver do Microsoft Paradox (*.db )                         odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.db
    Driver para o Microsoft Visual FoxPro                       vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Access Driver (*.mdb)                             odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.mdb
    Microsoft Access-Treiber (*.mdb)                            odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.mdb
    Microsoft dBase Driver (*.dbf)                              odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.dbf,*.ndx,*.mdx
    Microsoft dBase VFP Driver (*.dbf)                          vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft dBase-Treiber (*.dbf)                             odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.dbf,*.ndx,*.mdx
    Microsoft Excel Driver (*.xls)                              odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.xls
    Microsoft Excel-Treiber (*.xls)                             odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.xls
    Microsoft FoxPro VFP Driver (*.dbf)                         vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft ODBC for Oracle                                   msorcl32.dll        6.1.7600.16385 (win7_rtm.090713-1255)  
    Microsoft Paradox Driver (*.db )                            odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.db
    Microsoft Paradox-Treiber (*.db )                           odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.db
    Microsoft Text Driver (*.txt; *.csv)                        odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Text-Treiber (*.txt; *.csv)                       odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Visual FoxPro Driver                              vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Visual FoxPro-Treiber                             vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    SQL Server                                                  sqlsrv32.dll        6.1.7600.16385 (win7_rtm.090713-1255)  


--------[    ]--------------------------------------------------------------------------------------------

    Core i7-2600            3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1            16210 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            14174 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            13899 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1            12400 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            11481 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9117 /
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             9084 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8862 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 7990 /
    A8-3850                 2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1             7980 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             7891 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 7870 /
    Core 2 Quad Q9550       2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2             7799 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             7437 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7134 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             7002 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 6686 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             6347 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             6181 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             5934 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5646 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 5375 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             5276 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             4920 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             4852 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4569 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              4353 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             4158 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 3966 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3909 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             3887 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 3547 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 3515 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3352 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 3238 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 3140 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2894 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2826 /


--------[    ]---------------------------------------------------------------------------------------------

    Core i7-2600            3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1            18434 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            12544 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            12064 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9555 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1             9417 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8836 /
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             7506 /
    Core 2 Quad Q9550       2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2             7088 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7052 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             6895 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 6711 /
    A8-3850                 2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1             6387 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             6341 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             5828 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             5711 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 5608 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 5592 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5362 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             4853 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4838 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             4452 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             4232 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4177 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4106 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3800 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             3785 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 3629 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             3581 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             3259 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3157 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 2816 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 2770 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2491 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 2443 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2342 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2322 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              2038 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             1661 /


--------[    ]----------------------------------------------------------------------------------------

    Core i7-2600            3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1            16340 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            14937 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            12610 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            11211 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1            10807 /
    A8-3850                 2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1            10641 /
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1            10557 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9534 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             9391 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             8321 /
    Core 2 Quad Q9550       2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2             7483 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             7094 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             6770 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             6663 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             6458 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             6200 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 6040 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 5951 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             5426 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 5421 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 4988 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             4764 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4615 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4585 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             4283 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 4223 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4052 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             3890 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3668 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             3268 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 3080 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 2966 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2891 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             2759 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2582 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              2518 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             2488 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 2375 /


--------[   ]---------------------------------------------------------------------------------------------

    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1       47.5 ns
    Core i7-2600            3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1       54.0 ns
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1       54.5 ns
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2       55.7 ns
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1       55.8 ns
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1       57.6 ns
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1       59.9 ns
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1       60.6 ns
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2       60.7 ns
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2       62.0 ns
    A8-3850                 2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1       62.6 ns
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2       62.8 ns
    Core 2 Quad Q9550       2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2       63.5 ns
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1       68.4 ns
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2       68.6 ns
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15           71.9 ns
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2       74.9 ns
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11           80.7 ns
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1        81.4 ns
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1       82.4 ns
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1       84.1 ns
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1       86.3 ns
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15           86.4 ns
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15           87.6 ns
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15           88.1 ns
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1        89.1 ns
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1       97.9 ns
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2      102.0 ns
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12          103.2 ns
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15          110.1 ns
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1      110.9 ns
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15          111.3 ns
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2      117.3 ns
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12          127.0 ns
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7         146.2 ns
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11          149.1 ns
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2      156.7 ns
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1      226.4 ns


--------[ CPU Queen ]---------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1         56780
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         53499
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1         44106
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         42524
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             41694
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         37793
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         30782
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1         27770
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             26972
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         25500
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2         24145
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1         22158
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             21994
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1         21978
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         21891
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1         21441
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1         21223
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             19169
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         16092
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1         12581
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2         12129
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1         11234
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              9597
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              7451
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          7301
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             7273
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1          5169
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          4981
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           4877
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          4084
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              4023
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           3852
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12              3790
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          3513
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              3298
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          2812
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2          2580
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11              1836


--------[ CPU PhotoWorxx ]----------------------------------------------------------------------------------------------

    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1                 60355
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1                 49120
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1                 47638
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1                 47066
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1                 46595
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1                 34806
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1                 31119
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                     27165
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2                 25933
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1                 24462
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1                 22012
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2                 20352
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1                 19947
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2                 19207
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2                 14576
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                     12294
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                      9478
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1                  9335
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                      8641
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                      8395
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1                  8384
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1                  7609
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2                  7353
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                      6975
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                      5530
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1                   5388
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                      5086
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1                  4976
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2                  4912
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2                  4817
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                     4430
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1                  4375
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2                  4249
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1                   3767
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2                  3212
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                      2514
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2                  2493
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                      2346


--------[ CPU ZLib ]----------------------------------------------------------------------------------------------------

    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1            348.9 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            343.9 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1            340.9 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1            274.2 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                269.0 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1            232.8 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            214.2 /
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1            208.2 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                180.5 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1            166.3 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2            147.6 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2            146.0 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1            145.3 /
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2            137.0 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                129.8 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                112.2 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2            107.3 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            103.5 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1            101.1 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             79.1 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             71.5 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             70.3 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 56.8 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                54.9 /
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 54.8 /
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             45.1 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             39.5 /
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             33.2 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             31.0 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 30.8 /
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              29.4 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              23.2 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             21.9 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 19.4 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 17.7 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 16.5 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             15.6 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             14.7 /


--------[ CPU AES ]-----------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1        352227
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1        324842
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1        207915
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         78761
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         65697
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             61006
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         53016
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1         46894
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         41013
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             40639
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2         40002
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1         35903
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         32973
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1         32934
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         32609
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2         30825
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             29287
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1         27679
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             25455
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         23408
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1         18744
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1         16738
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2         16170
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15             12357
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11             10926
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2         10810
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7            10643
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          7552
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          7445
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           7123
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1          6526
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              5848
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           5659
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          5241
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              4397
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          4193
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11              3355
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12              1973


--------[ CPU Hash ]----------------------------------------------------------------------------------------------------

    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             4784 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 3609 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             3188 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1             3132 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             3095 /
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             2806 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2347 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2242 /
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1             2222 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             1989 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             1942 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1             1941 /
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1             1914 /
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2             1827 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 1681 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1             1656 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 1465 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             1441 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             1101 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1              980 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1              968 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2              925 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                  828 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                 808 /
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                  728 /
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2              638 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2              549 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2              493 /
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1              448 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                  442 /
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1               427 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1               336 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1              326 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2              306 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                  251 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                  247 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2              245 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                  162 /


--------[ FPU VP8 ]-----------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1                  3683
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1                  3428
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1                  3304
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                      3005
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1                  2894
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1                  2790
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1                  2772
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1                  2768
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2                  2288
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1                  2190
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2                  2073
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1                  2069
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2                  1959
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1                  1803
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                      1798
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1                  1772
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                      1733
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2                  1532
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                      1457
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2                  1127
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1                  1107
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1                  1007
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                       888
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                       744
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                      693
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2                   652
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1                   632
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2                   556
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2                   518
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                       471
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1                   457
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                       451
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1                    413
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2                   413
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                       401
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1                    393
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2                   318
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                       310


--------[ FPU Julia ]---------------------------------------------------------------------------------------------------

    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1         18518
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         18308
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1         17997
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         17671
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             15287
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         12204
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         11131
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1         10731
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              8954
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          8678
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          8201
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          8070
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2          7756
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          7606
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1          7433
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              6416
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              5596
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          5578
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          5549
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          3533
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              3077
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              2449
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             2385
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          2308
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          2052
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          1988
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          1703
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          1340
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              1307
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               960
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           914
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            896
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               892
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           795
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            702
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           640
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               589
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           513


--------[ FPU Mandel ]--------------------------------------------------------------------------------------------------

    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1          9817
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1          9318
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          8672
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1          8614
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              8067
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1          6212
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          5465
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          5397
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              4626
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          4418
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          4332
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          4180
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2          4079
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1          3968
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          3874
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              3313
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              2889
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          2840
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          2675
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1823
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              1626
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              1482
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             1449
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          1182
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          1062
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1051
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1           871
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               794
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2           683
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               495
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               476
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            458
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           428
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           407
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            360
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           328
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           263
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               193


--------[ FPU SinJulia ]------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          7473
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1          6993
    4x Core i7-2600 HT      3400   Asus P8P67                                                              P67                   Dual DDR3-1333        9-9-9-24 CR1          4694
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1          4658
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          4590
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              4138
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1          3101
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          2728
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              2590
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          2306
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          2266
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          2222
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          2210
    4x Core 2 Quad Q9550    2833   Asus Maximus II Formula                                                 P45                   Dual DDR2-1066        5-5-5-15 CR2          2101
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          1934
    4x A8-3850              2900   Gigabyte GA-A75M-UD2H                                                   A75 Int.              Dual DDR3-1333        9-9-9-24 CR1          1871
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              1855
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              1618
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          1421
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          1178
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1049
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1021
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11               960
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7              942
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15               835
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2           682
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               516
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           506
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            457
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2           452
    Sempron 140             2700   Asus Sabertooth 990FX                                                   AMD990FX              Unganged Dual DDR3-1333  9-9-9-24 CR1           435
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            359
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           327
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               277
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           262
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               205
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               203
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           132


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  Intel G43/G45/P43/P45 Chipset - Memory Controller Hub [A-2]
                  
      Offset 000:  86 80 20 2E  06 00 90 20  02 00 00 06  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 D3 82 
      Offset 030:  00 00 00 00  E0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 90 D1 FE  00 00 00 00  01 40 D1 FE  00 00 00 00 
      Offset 050:  00 00 00 00  03 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  01 00 00 E0  00 00 00 00  01 80 D1 FE  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  10 11 11 00  00 33 33 00  80 00 87 00  00 1A 38 00 
      Offset 0A0:  80 00 00 22  00 00 00 E0  00 00 00 E0  00 00 00 E0 
      Offset 0B0:  00 E0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  03 03 00 00  60 66 66 13  00 00 00 4B 
      Offset 0E0:  09 00 0C 81  20 45 37 88  D2 4D 0B 80  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  A6 0F 02 00  00 00 00 00 

    B00 D01 F00:  Intel G43/G45/P43/P45 Chipset - Primary PCI Express x16 Root [A-2]
                  
      Offset 000:  86 80 21 2E  07 01 10 00  02 00 04 06  08 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 01 01 00  A0 A0 00 20 
      Offset 020:  00 FD 70 FE  01 F0 F1 F9  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  88 00 00 00  00 00 00 00  10 01 1A 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 02 
      Offset 080:  01 90 03 C8  08 00 00 00  0D 80 00 00  43 10 D3 82 
      Offset 090:  05 A0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  10 00 42 01  00 80 00 00  00 00 00 00  02 25 21 02 
      Offset 0B0:  40 00 01 51  80 25 00 00  00 00 48 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  02 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 01 00  03 41 3F 80  90 0F 02 00  00 F0 00 F0 

    B00 D1A F00:  Intel 82801JB ICH10 - USB Universal Host Controller
                  
      Offset 000:  86 80 37 3A  05 00 90 02  00 00 03 0C  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  01 98 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  09 00 06 20  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  10 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 2F 00 00  00 00 00 00  00 00 01 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1A F01:  Intel 82801JB ICH10 - USB Universal Host Controller
                  
      Offset 000:  86 80 38 3A  05 00 90 02  00 00 03 0C  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  81 98 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  15 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  09 00 06 20  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  10 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 2F 00 00  00 00 00 00  00 00 01 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1A F02:  Intel 82801JB ICH10 - USB Universal Host Controller
                  
      Offset 000:  86 80 39 3A  05 00 90 02  00 00 03 0C  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  01 9C 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 03 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  09 00 06 20  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  10 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 2F 00 00  00 00 00 00  00 00 01 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1A F07:  Intel 82801JB ICH10 - USB2 Enhanced Host Controller
                  
      Offset 000:  86 80 3C 3A  06 00 90 02  00 20 03 0C  00 00 00 00 
      Offset 010:  00 FC FF FC  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 03 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 C2 C9  00 00 00 00  0A 98 A0 20  00 00 00 00 
      Offset 060:  20 20 FF 01  00 00 00 00  01 00 00 00  00 20 00 C0 
      Offset 070:  00 00 CF 0F  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  01 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  09 00 06 20  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 AA FF 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  86 85 40 00  86 0F 00 00  0A 13 02 20 

    B00 D1B F00:  Intel 82801JB ICH10 - High Definition Audio Controller
                  
      Offset 000:  86 80 3E 3A  06 00 10 00  00 00 03 04  08 00 00 00 
      Offset 010:  04 80 FF FC  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 34 83 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  16 01 00 00 
      Offset 040:  01 00 00 07  07 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 60 42 C8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  05 70 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  10 00 91 00  00 00 00 10  00 08 10 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 04 00 01  00 00 00 00  31 00 A3 02  00 00 00 00 
      Offset 0D0:  61 00 A3 02  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1C F00:  Intel 82801JB ICH10 - PCI Express Root Port 1
                  
      Offset 000:  86 80 40 3A  06 01 10 00  00 00 04 06  08 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 05 05 00  F0 00 00 20 
      Offset 020:  F0 FF 00 00  F1 FB F1 FB  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  11 01 02 00 
      Offset 040:  10 80 41 01  00 80 00 00  00 00 10 00  11 2C 11 01 
      Offset 050:  40 00 01 10  60 05 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  05 90 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  0D A0 00 00  43 10 D4 82  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 02 C8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 11 08  00 00 00 00 
      Offset 0E0:  00 00 C7 00  06 07 08 00  30 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1C F02:  Intel 82801JB ICH10 - PCI Express Root Port 3
                  
      Offset 000:  86 80 44 3A  07 01 10 00  00 00 04 06  08 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 04 04 00  D0 D0 00 00 
      Offset 020:  A0 FE A0 FE  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  12 03 02 00 
      Offset 040:  10 80 41 01  00 80 00 00  00 00 10 00  11 2C 11 03 
      Offset 050:  40 00 11 30  60 05 00 00  00 00 48 01  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  05 90 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  0D A0 00 00  43 10 D4 82  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 02 C8  00 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 11 08  00 00 00 00 
      Offset 0E0:  00 00 C7 00  06 07 08 00  30 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1C F03:  Intel 82801JB ICH10 - PCI Express Root Port 4
                  
      Offset 000:  86 80 46 3A  07 01 10 00  00 00 04 06  08 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 03 03 00  C0 C0 00 00 
      Offset 020:  90 FE 90 FE  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  13 04 02 00 
      Offset 040:  10 80 41 01  00 80 00 00  00 00 10 00  11 2C 11 04 
      Offset 050:  40 00 11 30  60 05 00 00  00 00 48 01  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  05 90 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  0D A0 00 00  43 10 D4 82  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 02 C8  00 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 11 08  00 00 00 00 
      Offset 0E0:  00 00 C7 00  06 07 08 00  30 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1C F04:  Intel 82801JB ICH10 - PCI Express Root Port 5
                  
      Offset 000:  86 80 48 3A  07 01 10 00  00 00 04 06  08 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 02 02 00  B0 B0 00 00 
      Offset 020:  80 FE 80 FE  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  11 01 02 00 
      Offset 040:  10 80 41 01  00 80 00 00  00 00 10 00  11 2C 11 05 
      Offset 050:  40 00 11 30  60 05 00 00  00 00 48 01  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  05 90 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  0D A0 00 00  43 10 D4 82  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 02 C8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 11 08  00 00 00 00 
      Offset 0E0:  00 00 C7 00  06 07 08 00  30 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1D F00:  Intel 82801JB ICH10 - USB Universal Host Controller
                  
      Offset 000:  86 80 34 3A  05 00 90 02  00 00 03 0C  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  81 90 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  17 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  09 00 06 20  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  10 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 2F 00 00  00 00 00 00  00 00 01 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1D F01:  Intel 82801JB ICH10 - USB Universal Host Controller
                  
      Offset 000:  86 80 35 3A  05 00 90 02  00 00 03 0C  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  01 94 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  09 00 06 20  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  10 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 2F 00 00  00 00 00 00  00 00 01 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1D F02:  Intel 82801JB ICH10 - USB Universal Host Controller
                  
      Offset 000:  86 80 36 3A  05 00 90 02  00 00 03 0C  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  81 94 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 03 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  09 00 06 20  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  10 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 2F 00 00  00 00 00 00  00 00 01 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1D F07:  Intel 82801JB ICH10 - USB2 Enhanced Host Controller
                  
      Offset 000:  86 80 3A 3A  06 00 90 02  00 20 03 0C  00 00 00 00 
      Offset 010:  00 F8 FF FC  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  17 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 C2 C9  00 00 00 00  0A 98 A0 20  00 00 00 00 
      Offset 060:  20 20 FF 01  00 00 00 00  01 00 00 00  00 20 00 C0 
      Offset 070:  00 00 DF 0F  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  01 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  09 00 06 20  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 AA FF 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  86 85 40 00  86 0F 00 00  0A 13 02 20 

    B00 D1E F00:  Intel 82801JB I/O Controller Hub 10 (ICH10) [A-0]
                  
      Offset 000:  86 80 4E 24  07 01 10 00  90 01 04 06  00 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 06 06 20  E0 E0 80 22 
      Offset 020:  B0 FE B0 FE  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  FF 00 02 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 12 00 00 
      Offset 050:  0D 00 00 00  43 10 D4 82  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1F F00:  Intel 82801JB ICH10R - LPC Bridge
                  
      Offset 000:  86 80 16 3A  07 00 10 02  00 00 01 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  E0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 08 00 00  80 00 00 00  01 05 00 00  10 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  8A 8B 8F 85  D0 00 00 00  80 8E 83 87  F8 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 0F 14  95 02 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  A0 06 00 00  39 00 01 00  13 1C 0A 24  00 03 00 00 
      Offset 0B0:  00 00 F0 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  33 22 11 00  67 45 00 00  C0 F0 00 00  00 00 00 00 
      Offset 0E0:  09 00 0C 10  01 00 C4 02  64 02 00 00  00 00 00 00 
      Offset 0F0:  01 C0 D1 FE  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1F F02:  Intel 82801JB ICH10 - 4-port SATA Controller
                  
      Offset 000:  86 80 20 3A  05 00 B0 02  00 8F 01 01  00 00 00 00 
      Offset 010:  01 80 00 00  01 7C 00 00  81 78 00 00  01 78 00 00 
      Offset 020:  81 74 00 00  01 74 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  70 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  07 A3 00 80  00 00 00 00  01 00 01 00  00 00 00 00 
      Offset 050:  00 00 00 00  30 10 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  01 B0 03 00  08 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  05 70 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 0F 81  93 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  09 00 06 20  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  05 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1F F03:  Intel 82801JB ICH10 - SMBus Controller
                  
      Offset 000:  86 80 30 3A  03 00 80 02  00 00 05 0C  00 00 00 00 
      Offset 010:  04 F4 FF FC  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  01 04 00 00  00 00 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  0F 03 00 00 
      Offset 040:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  03 04 04 00  00 00 08 08  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  04 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B00 D1F F05:  Intel 82801JB ICH10 - 2-port SATA Controller
                  
      Offset 000:  86 80 26 3A  05 00 B0 02  00 85 01 01  00 00 00 00 
      Offset 010:  01 90 00 00  01 8C 00 00  81 88 00 00  01 88 00 00 
      Offset 020:  81 84 00 00  01 84 00 00  00 00 00 00  43 10 D4 82 
      Offset 030:  00 00 00 00  70 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  00 80 00 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  01 B0 03 00  08 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  05 70 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 03 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  09 00 06 20  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  86 0F 00 00  00 00 00 00 

    B01 D00 F00:  Zotac GeForce GTX 580 Video Adapter
                  
      Offset 000:  DE 10 80 10  07 00 10 00  A1 00 00 03  08 00 80 00 
      Offset 010:  00 00 00 FD  0C 00 00 F0  00 00 00 00  0C 00 00 F8 
      Offset 020:  00 00 00 00  01 AC 00 00  00 00 00 00  DA 19 03 12 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  DA 19 03 12  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 00 00 00  01 00 00 00  CE D6 23 00  00 00 00 00 
      Offset 060:  01 68 03 00  08 00 00 00  05 78 80 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  10 B4 02 00  E0 8D 2C 01 
      Offset 080:  10 29 00 00  01 2D 05 00  48 01 01 11  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  10 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  01 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  09 00 14 01  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B01 D00 F01:  nVIDIA GF110 - High Definition Audio Controller
                  
      Offset 000:  DE 10 09 0E  06 00 10 00  A1 00 03 04  08 00 80 00 
      Offset 010:  00 C0 7F FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  DA 19 03 12 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  11 02 00 00 
      Offset 040:  DA 19 03 12  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  CE D6 23 00  00 00 00 00 
      Offset 060:  01 68 03 00  08 00 00 00  05 78 80 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  10 00 02 00  A0 8D 2C 01 
      Offset 080:  10 28 00 00  01 2D 05 00  0B 01 01 11  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  10 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F00:  Marvell 88SE6121 Serial ATA II Host Controller
                  
      Offset 000:  AB 11 21 61  07 00 10 00  B1 8F 01 01  08 00 00 00 
      Offset 010:  01 BC 00 00  81 B8 00 00  01 B8 00 00  81 B4 00 00 
      Offset 020:  01 B4 00 00  00 FC 8F FE  00 00 00 00  AB 11 21 61 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  24 C9 C0 00  1F 80 00 00  01 50 02 5A  00 20 00 13 
      Offset 050:  05 E0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  50 C4 21 40  B0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  10 00 11 00  C0 0F 08 00  00 24 08 00  11 A4 03 00 
      Offset 0F0:  00 00 11 10  00 00 00 00  00 00 00 00  00 00 00 00 

    B03 D00 F00:  Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
                  
      Offset 000:  AB 11 64 43  07 00 10 00  12 00 00 02  08 00 00 00 
      Offset 010:  04 C0 9F FE  00 00 00 00  01 C8 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 F8 81 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  13 01 00 00 
      Offset 040:  00 00 F0 01  00 80 A0 01  01 50 03 FE  00 21 00 13 
      Offset 050:  03 5C 00 80  00 00 00 01  00 00 00 01  05 E0 80 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 03 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 70 00 00  00 00 00 00  82 A8 E8 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  10 00 11 00  C0 8F 28 00  00 40 19 00  11 AC 07 00 
      Offset 0F0:  08 00 11 10  00 00 00 00  00 00 00 00  00 00 00 00 

    B04 D00 F00:  Marvell Yukon 88E8056 PCI-E Gigabit Ethernet Controller
                  
      Offset 000:  AB 11 64 43  07 00 10 00  12 00 00 02  08 00 00 00 
      Offset 010:  04 C0 AF FE  00 00 00 00  01 D8 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 F8 81 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  00 00 F0 01  00 80 A0 01  01 50 03 FE  00 21 00 13 
      Offset 050:  03 5C 00 80  00 00 00 01  00 00 00 01  05 E0 80 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 04 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 70 00 00  00 00 00 00  82 A8 E8 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  10 00 11 00  C0 8F 28 00  00 40 19 00  11 AC 07 00 
      Offset 0F0:  08 00 11 10  00 00 00 00  00 00 00 00  00 00 00 00 

    B06 D00 F00:  Compex RE100ATX Fast Ethernet Adapter
                  
      Offset 000:  EC 10 39 81  07 00 90 02  10 00 00 02  00 40 00 00 
      Offset 010:  01 E8 00 00  00 FC BF FE  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  F6 11 39 81 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  10 01 20 40 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 00 C2 F7  00 01 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B06 D03 F00:  VIA VT6308 Fire IIM IEEE1394 Host Controller
                  
      Offset 000:  06 11 44 30  17 00 10 02  C0 10 00 0C  08 40 00 00 
      Offset 010:  00 F0 BF FE  01 EC 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 FE 81 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  13 01 00 20 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 00 02 E4  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    PCI-8086-2E20:  Intel 3-series/4-series/32xx MCHBAR
                  
      Offset 100:  00 00 00 00  00 20 00 00  00 10 00 10  00 00 00 00 
      Offset 110:  45 AC 00 00  00 9A 01 AA  48 10 7E 81  00 08 7D 00 
      Offset 120:  5F 7F 8D 50  07 E0 3B 40  05 1F 80 00  10 54 00 5C 
      Offset 130:  A2 FF A9 9F  00 3C A6 29  9F D0 91 40  9C CF 81 40 
      Offset 140:  8A 52 32 01  89 22 32 01  5D D7 7A 01  1B B7 72 01 
      Offset 150:  00 00 00 00  00 00 00 00  00 00 00 00  C5 51 1C 06 
      Offset 160:  99 09 00 00  23 13 1F 13  00 00 00 00  00 00 00 00 
      Offset 170:  00 00 00 00  FF 73 00 00  35 01 00 00  00 FF FF FF 
      Offset 180:  04 0D C8 00  FF FF FF FF  1B BF 0F 0F  00 00 00 00 
      Offset 190:  00 00 01 0F  33 00 00 00  AA AA AA 22  18 30 00 00 
      Offset 1A0:  03 18 55 00  40 00 00 00  F1 00 00 00  DF 00 00 00 
      Offset 1B0:  00 03 00 00  C0 01 00 00  00 00 00 00  02 04 06 08 
      Offset 1C0:  20 01 00 00  00 80 00 00  0D 00 00 00  00 00 00 00 
      Offset 1D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1E0:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 200:  10 00 20 00  30 00 40 00  86 86 86 86  00 00 00 00 
      Offset 210:  3F 00 7F FF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 220:  17 11 00 58  01 02 22 00  02 00 00 00  00 00 00 00 
      Offset 230:  00 00 00 00  00 00 00 00  00 13 00 00  89 7B 00 00 
      Offset 240:  02 11 00 01  10 23 05 00  33 66 C5 0E  00 11 3F 00 
      Offset 250:  95 03 34 AC  86 04 77 54  45 B5 0A 34  0C 0F A5 15 
      Offset 260:  C8 3C F7 0B  78 00 0B 13  4A 4B D0 CF  33 5F 25 03 
      Offset 270:  00 0E 55 01  01 87 08 00  81 18 14 88  41 00 04 48 
      Offset 280:  00 00 00 00  00 00 00 00  00 02 04 08  10 20 40 FF 
      Offset 290:  1C 09 F2 04  11 11 00 00  44 44 00 00  6B 06 00 00 
      Offset 2A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 2B0:  00 00 00 00  00 00 00 00  00 18 06 00  70 70 70 00 
      Offset 2C0:  F0 C5 0C 48  7C 00 00 00  00 00 00 00  00 00 00 00 
      Offset 2D0:  00 31 28 FF  00 36 45 40  00 00 00 00  00 00 00 00 
      Offset 2E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 2F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    PCI-8086-2E20:  Intel 3-series/4-series/32xx MCHBAR
                  
      Offset 500:  17 17 17 17  17 17 17 17  66 66 66 66  66 66 66 66 
      Offset 510:  26 26 26 26  25 25 25 25  42 42 42 42  60 60 60 60 
      Offset 520:  01 01 01 01  01 01 01 01  50 50 50 50  50 50 50 50 
      Offset 530:  10 10 10 10  2B 2B 2B 2B  48 48 48 48  56 56 56 56 
      Offset 540:  44 55 B6 00  66 55 00 00  55 55 DB 00  55 55 6D 00 
      Offset 550:  66 55 00 00  66 55 DB 00  55 55 DB 00  55 55 DB 00 
      Offset 560:  73 00 00 00  78 00 00 00  74 00 00 00  74 00 00 00 
      Offset 570:  7A 00 00 00  77 00 00 00  76 00 00 00  75 00 00 00 
      Offset 580:  11 44 44 00  11 11 11 11  00 00 00 00  FB FE 00 00 
      Offset 590:  55 55 38 1E  68 00 00 80  00 33 00 00  00 C0 F1 00 
      Offset 5A0:  10 40 01 00  C0 80 01 00  C0 80 01 00  C0 80 01 00 
      Offset 5B0:  C0 80 01 00  1F 7E 00 00  1F 7E 00 00  1F 7E 00 00 
      Offset 5C0:  1F 7E 00 00  07 18 00 00  00 00 00 54  00 00 00 54 
      Offset 5D0:  00 00 00 54  00 00 00 54  0F 72 00 00  80 3F 00 00 
      Offset 5E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 5F0:  FC 07 00 00  00 00 00 00  00 00 00 00  33 33 13 11 
      Offset 600:  10 00 20 00  30 00 40 00  86 86 86 86  00 00 00 00 
      Offset 610:  32 32 64 28  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 620:  17 11 00 58  01 02 22 00  02 00 00 00  00 00 00 04 
      Offset 630:  00 00 00 00  00 00 00 00  00 13 00 00  89 7B 00 00 
      Offset 640:  02 11 00 01  10 23 25 00  33 66 C5 0E  00 11 3F 00 
      Offset 650:  95 03 34 AC  86 04 77 54  45 B5 0A 34  0C 0F A5 15 
      Offset 660:  C8 3C F7 0B  78 00 0B 13  4A 4B D0 CF  33 5F 25 03 
      Offset 670:  00 0E 55 01  01 87 08 00  81 18 14 88  41 00 04 48 
      Offset 680:  00 00 00 00  00 00 00 00  00 02 04 08  10 20 40 FF 
      Offset 690:  1C 09 F2 04  11 11 00 00  44 44 00 00  6B 06 00 00 
      Offset 6A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 6B0:  00 00 00 00  00 00 00 00  00 18 06 00  70 70 70 01 
      Offset 6C0:  A0 34 20 80  02 00 00 00  00 00 00 00  00 00 00 00 
      Offset 6D0:  00 00 1D 0F  00 00 00 00  00 00 00 00  08 02 01 10 
      Offset 6E0:  00 00 00 00  08 02 01 10  00 00 00 04  02 01 00 08 
      Offset 6F0:  00 00 00 04  02 01 00 08  00 00 00 00  00 00 00 00 

    PCI-8086-2E20:  Intel 3-series/4-series/32xx MCHBAR
                  
      Offset 900:  54 54 54 54  54 54 54 54  63 63 63 63  63 63 63 63 
      Offset 910:  42 42 42 42  61 61 61 61  10 10 10 10  10 10 10 10 
      Offset 920:  4A 4A 4A 4A  4A 4A 4A 4A  59 59 59 59  59 59 59 59 
      Offset 930:  38 38 38 38  67 67 67 67  06 06 06 06  06 06 06 06 
      Offset 940:  44 55 6D 00  55 55 92 00  55 55 24 00  66 55 49 00 
      Offset 950:  66 55 00 00  55 55 6D 00  44 55 B6 00  55 55 49 00 
      Offset 960:  70 00 00 00  74 00 00 00  76 00 00 00  75 00 00 00 
      Offset 970:  72 00 00 00  79 00 00 00  72 00 00 00  73 00 00 00 
      Offset 980:  11 42 42 00  11 11 11 11  00 00 00 00  FC 0C 00 00 
      Offset 990:  55 55 18 1E  68 00 00 80  00 33 00 00  00 C0 F1 00 
      Offset 9A0:  D0 4C 01 00  F0 E0 01 00  F0 E0 01 00  F0 E0 01 00 
      Offset 9B0:  F0 E0 01 00  00 1E 00 00  00 1E 00 00  00 1E 00 00 
      Offset 9C0:  00 1E 00 00  07 18 00 00  00 00 55 55  00 00 55 55 
      Offset 9D0:  00 00 55 55  00 00 55 55  0F 72 00 00  00 3F 00 00 
      Offset 9E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 9F0:  FC 03 00 00  00 00 00 00  00 00 01 51  11 11 11 11 

    PCI-8086-2E20:  Intel 3-series/4-series/32xx MCHBAR
                  
      Offset C00:  44 24 01 40  0F 0F 0F 0F  80 00 00 00  00 00 00 00 
      Offset C10:  00 00 00 00  00 00 00 00  00 00 00 00  00 80 00 00 
      Offset C20:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C30:  01 00 00 00  00 00 00 00  02 00 00 00  80 C1 00 00 
      Offset C40:  00 80 00 02  00 00 00 00  00 80 00 00  00 00 00 00 
      Offset C50:  6B 1F 1F 6B  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C80:  01 01 01 01  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset CA0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset CB0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset CC0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset CD0:  00 00 00 00  00 00 00 00  00 00 00 FF  00 00 00 00 
      Offset CE0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset CF0:  00 00 00 00  03 00 00 00  00 00 00 00  00 00 00 00 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U.m.K7400.L.w.VIDEO ......<...IBM VGA Compatible.......N02/10/11
    C000:0040  ..........@.y.....*....................HN....D..DPMIDl.o.......
    C000:0080  .....3GF110 P1261 SKU 0002 VGA BIOS.............................
    C000:00C0  .......................Version 70.10.20.00.01 ...Copyright (C) 1
    C000:0100  996-2010 NVIDIA Corp.........C....GF110 Board - 12610002........
    C000:0140  .....Chip Rev   ................................................
    C000:0180  ........PCIR............m.......HYB$..BIT......E2...,.B.!.8.C...
    C000:01C0  Y.D...g.A...k.I...n.L.....M.....N.....P.0...S.....T.....U.....V.
    C000:0200  ....x.....d.....p.....i.B.....>..H.[.b................... .p.u..
    C000:0240  ..............\\....0............}Ix....L.A....J.J.J.JaL.L.J_..L
    C000:0280  ...fI6J.g...h...J...b..Fc..Ne...f..gg.......g..w....f...f...g..6
    C000:02C0  g....P.....(.H..H#".#E..wM.H.KI.I..........3C..h...h<........ .p
    C000:0300  ...PP}.....12/10/10.........................375012610002........
    C000:0340  ........Z.S.................p[ .........Z.S.........,.....p[1.y.
    C000:0380  y...5.y...........6.6.G.....L.q.@...Q...Z.......!.x...y.y...y.y.
    C000:03C0  ....a.y.....f...............n.....q.....t.e.$.q.x.S.z...........


--------[ Debug - Unknown ]---------------------------------------------------------------------------------------------

    Optical         EDQPEB CX2J4HYRKP2B SCSI CdRom Device


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
