--------[ AIDA64 Extreme Edition ]--------------------------------------------------------------------------------------

                                                AIDA64 v1.60.1300/ru
                                        2.7.345-x64
                                      http://www.aida64.com/
                                              
                                             -
                                             
                                   Microsoft Windows 7 Ultimate 6.1.7601 (Win7 RTM)
                                                  2012-02-22
                                                 16:18


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI x64-based PC
                                     Microsoft Windows 7 Ultimate
                                       Service Pack 1
      Internet Explorer                                 8.0.7601.17514
      DirectX                                           DirectX 11.0
                                           -
                                         
                                              -
       /                                       2012-02-22 / 16:18

     :
                                                   DualCore AMD Athlon 64 X2, 2600 MHz (13 x 200) 5000+
                                          Asus M2N  (3 PCI, 2 PCI-E x1, 1 PCI-E x16, 4 DDR2 DIMM, Audio, Gigabit LAN)
                                    nVIDIA nForce 6100-430, AMD Hammer
                                         4096   (DDR2-800 DDR2 SDRAM)
      DIMM1:                                            2  DDR2-800 DDR2 SDRAM  (6-6-6-18 @ 400 )  (5-5-5-15 @ 333 )
      DIMM2:                                            2  DDR2-800 DDR2 SDRAM  (6-6-6-18 @ 400 )  (5-5-5-15 @ 333 )  (4-4-4-12 @ 266 )
       BIOS                                          AMI (09/13/07)
                                      (COM1)
                                      (LPT1)

    :
                                            ATI Radeon HD 5500 Series  (1024 )
                                            ATI Radeon HD 5500 Series  (1024 )
      3D-                                    ATI Radeon HD 5570 (Redwood)
                                                 Samsung SyncMaster 720N  [17" LCD]  (H9FM472938)

    :
                                         ATI Radeon HDMI @ ATI Redwood/Madison - High Definition Audio Controller
                                         C-Media CMI8738/C3DX Audio Device

     :
       IDE                                       PCI IDE
                                 NVIDIA nForce Serial ATA
                                 NVIDIA nForce Serial ATA
      -                                 
                                      ADATA NH13 USB Device  (465 , USB)
                                      SAMSUNG HD120IJ SCSI Disk Device  (120 , 7200 RPM, SATA-II)
                                    Optiarc DVD RW AD-7173A ATA Device  (DVD+R9:8x, DVD-R9:8x, DVD+RW:18x/8x, DVD-RW:18x/6x, DVD-RAM:12x, DVD-ROM:16x, CD:48x/32x/48x DVD+RW/DVD-RW/DVD-RAM)
       SMART                         OK

    :
      C: (NTFS)                                         111.8  (90.4  )
      E: (NTFS)                                         465.8  (265.4  )
                                              577.5  (355.8  )

    :
                                                PS/2
                                                    Microsoft PS/2 

    :
        IP                                192.168.1.3
        MAC                               00-1F-C6-C3-30-E5
                                            NVIDIA nForce  (192.168.1.3)

     :
                                                 Fax
                                                 Microsoft XPS Document Writer
       USB1                                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - OHCI USB 1.1 Controller
       USB2                                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - EHCI USB 2.0 Controller
      USB-                                    FaceCam 300
      USB-                                       USB

    DMI:
      DMI  BIOS                                American Megatrends Inc.
      DMI  BIOS                                   0803
      DMI                           System manufacturer
      DMI                                        System Product Name
      DMI                                System Version
      DMI                         System Serial Number
      DMI  UUID                                D0CDDCA8-74FED511-BCA58E29-03C55E8E
      DMI                    ASUSTeK Computer INC.
      DMI                                 M2N
      DMI                           Rev 1.xx
      DMI                    MB-1234567890
      DMI                             Chassis Manufacture
      DMI                                    Chassis Version
      DMI                             Chassis Serial Number
      DMI Asset-                                Asset-1234567890
      DMI                                       Desktop Case
      DMI  /                 4 / 2


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 -
      DNS               -
      DNS              
      DNS              -
     NetBIOS                 -
      DNS               -
      DNS              
      DNS              -


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           American Megatrends Inc.
                                                  0803
                                             09/13/2007
                                                  512 
                                   Floppy Disk, Hard Disk, CD-ROM, ATAPI ZIP, LS-120
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS
                                 DMI, APM, ACPI, ESCD, PnP
                                   ISA, PCI, USB

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                   http://www.aida64.com/bios-updates

  [  ]

     :
                                           System manufacturer
                                                 System Product Name
                                                  System Version
                                           System Serial Number
      SKU#                                              To Be Filled By O.E.M.
                                               To Be Filled By O.E.M.
        ID                       D0CDDCA8-74FED511-BCA58E29-03C55E8E
                                           

  [   ]

      :
                                           ASUSTeK Computer INC.
                                                 M2N
                                                  Rev 1.xx
                                           MB-1234567890

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/ProductGroup2.aspx?PG_ID=mKyCKlQ4oSEtSu5m
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates
       BIOS                                   http://www.aida64.com/bios-updates

  [  ]

     :
                                           Chassis Manufacture
                                                  Chassis Version
                                           Chassis Serial Number
                                            Asset-1234567890
                                                
                                     
                               
                                  
                                   

  [   ]

      :
                                  64-bit ECC
                                         
                              1-Way
                                1-Way
                             70ns, 60ns
                                DIMM, SDRAM
                   3.3V
                           4096 
                                           4

  [  / AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ ]

     :
                                           AMD
                                                  AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
                                           To Be Filled By O.E.M.
                                            To Be Filled By O.E.M.
                                          To Be Filled By O.E.M.
                                          200 
                                     2600 
                                          2600 
                                                     Central Processor
                                       1.5 V
                                                  
                                              CPU 1

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

  [ - / L1-Cache ]

     :
                                                     
                                                  
                                             Varies with Memory Address
                                         4-way Set-Associative
                                       256 
                                      256 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Single-bit ECC
                                              L1-Cache

  [ - / L2-Cache ]

     :
                                                     
                                                  
                                             Varies with Memory Address
                                         4-way Set-Associative
                                       1024 
                                      1024 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Single-bit ECC
                                              L2-Cache

  [ - / L3-Cache ]

     :
                                                     
                                                  
                                       0 
                                      0 
                                              L3-Cache

  [   / DIMM0 ]

      :
                                              DIMM0
                                                     DIMM
                                                160 ns
                                      2048 
                                         2048 

  [   / DIMM1 ]

      :
                                              DIMM1
                                                     DIMM
                                                162 ns
                                      2048 
                                         2048 

  [   / DIMM2 ]

      :
                                              DIMM2
                                                164 ns
                                       
                                          

  [   / DIMM3 ]

      :
                                              DIMM3
                                                166 ns
                                       
                                          

  [   / DIMM0 ]

      :
      -                                       DIMM
                                                     DDR2
                                                     Synchronous
                                                  2048 
                                                800 
                                             64 
                                            72 
                                              DIMM0
                                                    BANK0
                                           Manufacturer0
                                           SerNum0
                                            AssetTagNum0
                                          PartNum0

  [   / DIMM1 ]

      :
      -                                       DIMM
                                                     DDR2
                                                     Synchronous
                                                  2048 
                                                800 
                                             64 
                                            72 
                                              DIMM1
                                                    BANK1
                                           Manufacturer1
                                           SerNum1
                                            AssetTagNum1
                                          PartNum1

  [   / DIMM2 ]

      :
      -                                       DIMM
                                              DIMM2
                                                    BANK2
                                           Manufacturer2
                                           SerNum2
                                            AssetTagNum2
                                          PartNum2

  [   / DIMM3 ]

      :
      -                                       DIMM
                                              DIMM3
                                                    BANK3
                                           Manufacturer3
                                           SerNum3
                                            AssetTagNum3
                                          PartNum3

  [   / PCIEX16 ]

      :
                                       PCIEX16
                                                     PCI-E x1
                                           
                                        x16
                                                   

  [   / PCIEX1 ]

      :
                                       PCIEX1
                                                     PCI-E x1
                                           
                                        x1
                                                   

  [   / PCIEX2 ]

      :
                                       PCIEX2
                                                     PCI-E x1
                                           
                                        x1
                                                   

  [   / PCI1 ]

      :
                                       PCI1
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI2 ]

      :
                                       PCI2
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI3 ]

      :
                                       PCI3
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PS2Mouse ]

      :
                                                Mouse Port
                                   PS/2 Mouse
                                    
                                      PS2Mouse
                                       PS/2

  [   / Keyboard ]

      :
                                                Keyboard Port
                                   PS/2 Keyboard
                                    
                                      
                                       PS/2

  [   / USB1 ]

      :
                                                USB
                                   USB1
                                    
                                      USB1
                                       USB

  [   / USB2 ]

      :
                                                USB
                                   USB2
                                    
                                      USB2
                                       USB

  [   / USB3 ]

      :
                                                USB
                                   USB3
                                    
                                      USB3
                                       USB

  [   / USB4 ]

      :
                                                USB
                                   USB4
                                    
                                      USB4
                                       USB

  [   / USB5 ]

      :
                                                USB
                                   USB5
                                    
                                      USB5
                                       USB

  [   / USB6 ]

      :
                                                USB
                                   USB6
                                    
                                      USB6
                                       USB

  [   / USB7 ]

      :
                                                USB
                                   USB7
                                    
                                      USB7
                                       USB

  [   / USB8 ]

      :
                                                USB
                                   USB8
                                    
                                      USB8
                                       USB

  [   / USB9 ]

      :
                                                USB
                                   USB9
                                    
                                      USB9
                                       USB

  [   / USB10 ]

      :
                                                USB
                                   USB10
                                    
                                      USB10
                                       USB

  [   / LPT 1 ]

      :
                                                Parallel Port ECP/EPP
                                   LPT Port
                                    
                                      LPT 1
                                       DB-25 pin male

  [   / COM A ]

      :
                                                Serial Port 16550A Compatible
                                   COM Port
                                    
                                      COM A
                                       DB-9 pin male

  [   / Audio Mic In ]

      :
                                                Audio Port
                                   Audio Mic In
                                    
                                      Audio Mic In
                                       Mini-jack (headphones)

  [   / Audio Line In ]

      :
                                                Audio Port
                                   Audio Line In
                                    
                                      Audio Line In
                                       Mini-jack (headphones)

  [   / Audio Line Out ]

      :
                                                Audio Port
                                   Audio Line Out
                                    
                                      Audio Line Out
                                       Mini-jack (headphones)

  [   / SPDIF ]

      :
                                   SPDIF
                                       

  [   / PRI IDE ]

      :
                                   PRI IDE
                                    On-Board IDE
                                       

  [   / FLOPPY ]

      :
                                   FLOPPY
                                    On-Board Floppy
                                       

  [   / FRONT PNL ]

      :
                                   FRONT PNL
                                    9 Pin Dual Inline (pin 10 cut)
                                       

  [   / CHASSIS REAR FAN ]

      :
                                   CHASSIS REAR FAN
                                       

  [   / CPU FAN ]

      :
                                   CPU FAN
                                       

  [   / Power FAN ]

      :
                                   Power FAN
                                       

  [   / SATA1 ]

      :
                                   SATA1
                                       

  [   / SATA2 ]

      :
                                   SATA2
                                       

  [   / SATA3 ]

      :
                                   SATA3
                                       

  [   / SATA4 ]

      :
                                   SATA4
                                       

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Video
                                                  

  [  ]

    :
      OEM String                                        001FC6C330E5
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   DualCore AMD Athlon 64 X2 5000+
                                             Brisbane
                                              BH-G1
      Engineering Sample                                
        CPUID                                      AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
       CPUID                                      00060FB1h

     :
                                               2611.8 MHz  (: 2600 MHz)
                                             13x
      CPU FSB                                           200.9 MHz  (: 200 MHz)
       HyperTransport                            1004.6 MHz
                                              373.1 MHz
       DRAM:FSB                              CPU/7

     :
       L1                                        64  per core  (Parity)
       L1                                      64  per core  (ECC)
       L2                                            512  per core  (On-Die, ECC, Full-Speed)

      :
      ID                                  63-0803-000001-00101111-091307-MCP61$A0626000_BIOS DATE: 09/13/07 11:13:56 VER: 08.00.12
                                          Asus M2N  (3 PCI, 2 PCI-E x1, 1 PCI-E x16, 4 DDR2 DIMM, Audio, Gigabit LAN)

       ():
                                    nVIDIA nForce 6100-430, AMD Hammer
                                          6-6-6-18  (CL-RCD-RP-RAS)
      Command Rate (CR)                                 2T
      DIMM1:                                            2  DDR2-800 DDR2 SDRAM  (6-6-6-18 @ 400 )  (5-5-5-15 @ 333 )
      DIMM2:                                            2  DDR2-800 DDR2 SDRAM  (6-6-6-18 @ 400 )  (5-5-5-15 @ 333 )  (4-4-4-12 @ 266 )

     BIOS:
        BIOS                               09/13/07
       BIOS                            07/16/10
      DMI  BIOS                                   0803

      :
                                            ATI Radeon HD 5570 (Redwood)
                                       Redwood Pro  (PCI Express 2.0 x16 1002 / 68D9, Rev 00)
                                               157   (: 650 MHz)
                                           200   (: 400 MHz)


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                         
                              
                          


--------[   ]----------------------------------------------------------------------------------------------

    Centrino (Carmel)  :
      : Intel Pentium M (Banias/Dothan)                 (DualCore AMD Athlon 64 X2)
      : Intel i855GM/PM                             (nVIDIA nForce 6100-430, AMD Hammer)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Sonoma)  :
      : Intel Pentium M (Dothan)                        (DualCore AMD Athlon 64 X2)
      : Intel i915GM/PM                             (nVIDIA nForce 6100-430, AMD Hammer)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Napa)  :
      : Intel Core (Yonah) / Core 2 (Merom)             (DualCore AMD Athlon 64 X2)
      : Intel i945GM/PM                             (nVIDIA nForce 6100-430, AMD Hammer)
      WLAN: Intel PRO/Wireless 3945                     
      : Centrino-                     

    Centrino (Santa Rosa)  :
      : Intel Core 2 (Merom/Penryn)                     (DualCore AMD Athlon 64 X2)
      : Intel GM965/PM965                           (nVIDIA nForce 6100-430, AMD Hammer)
      WLAN: Intel Wireless WiFi Link 4965               
      : Centrino-                     

    Centrino 2 (Montevina)  :
      : Intel Core 2 (Penryn)                           (DualCore AMD Athlon 64 X2)
      : Intel GM45/GM47/GS45/PM45                   (nVIDIA nForce 6100-430, AMD Hammer)
      WLAN: Intel WiFi Link 5000 Series                 
      : Centrino 2-                   

    Centrino (Calpella)  :
      : Intel Core i3/i5/i7 (Arrandale/Clarksfield)     (DualCore AMD Athlon 64 X2)
      : Intel HM55/HM57/PM55                        (nVIDIA nForce 6100-430, AMD Hammer)
      WLAN: Intel WiFi Link 1000/WiMAX 6000 Series      
      : Centrino-                     


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                              ITE IT8716F  (ISA 290h)
                                            Diode  (ATI-Diode)
                                          Asus M2N
                               

    :
                                          36 C  (97 F)
                                                      21 C  (70 F)
       1 /  1                                     24 C  (75 F)
       1 /  2                                     35 C  (95 F)
      MCP                                               63 C  (145 F)
                                                  38 C  (100 F)
      SAMSUNG HD120IJ                                   38 C  (100 F)
      TOSHIBA MK5059GSXP                                30 C  (86 F)

    :
                                                      3140 RPM
                                    15%

    :
                                                  1.344 V
      +3.3 V                                            3.296 V
      +5 V                                              4.999 V
      +12 V                                             12.044 V
       VBAT                                      3.040 V
      Debug Info F                                      00D7 FFFF FFFF 0000 0000
      Debug Info T                                      21 36 128
      Debug Info V                                      54 FF CE FF BF E4 FF FF BE


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   DualCore AMD Athlon 64 X2, 2600 MHz (13 x 200) 5000+
                                             Brisbane
                                              BH-G1
                                        x86, x86-64, MMX, 3DNow!, SSE, SSE2, SSE3
                                         2600 
      ./.                             4x / 13x
      Engineering Sample                                
       L1                                        64  per core  (Parity)
       L1                                      64  per core  (ECC)
       L2                                            512  per core  (On-Die, ECC, Full-Speed)

    Multi CPU:
      ID                                  TEMPLATE
      CPU #1                                            AMD Athlon(tm) 64 X2 Dual Core Processor 5000+, 2611 
      CPU #2                                            AMD Athlon(tm) 64 X2 Dual Core Processor 5000+, 2611 

       :
                                              940 Pin uOPGA
                                          4.00 cm x 4.00 cm
                                       154 .
                                  10Mi, 65 nm, CMOS, Cu, DSL SOI
                                         126 mm2
                                   1.100 - 1.375 V
       I/O                                    1.2 V + 2.5 V
                                    65 - 76 W  (   )

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

     :
       1 /  1                                     0 %
       1 /  2                                     25 %


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               AuthenticAMD
        CPUID                                      AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
       CPUID                                      00060FB1h
        CPUID                          00060FB1h
       AMD                                 08D9h  (Athlon 64 X2 5000+)
                                  D5h  (Socket AM2)
      HTT / CMP                                         0 / 2

     :
      64- x86- (AMD64, Intel64)            
      AMD 3DNow!                                        
      AMD 3DNow! Professional                           
      AMD 3DNowPrefetch                                 
      AMD Enhanced 3DNow!                               
      AMD Extended MMX                                  
      AMD FMA4                                           
      AMD MisAligned SSE                                 
      AMD SSE4A                                          
      AMD XOP                                            
      Cyrix Extended MMX                                 
      Float-16 Conversion Instructions                   
      IA-64                                              
      IA MMX                                            
      IA SSE                                            
      IA SSE 2                                          
      IA SSE 3                                          
      IA Supplemental SSE 3                              
      IA SSE 4.1                                         
      IA SSE 4.2                                         
      IA AVX                                             
      IA FMA                                             
      IA AES Extensions                                  
      VIA Alternate Instruction Set                      
       CLFLUSH                                
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       LZCNT                                   
       MONITOR / MWAIT                         
       MOVBE                                   
       PCLMULQDQ                               
       POPCNT                                  
       RDRAND                                  
       RDTSCP                                 
       SYSCALL / SYSRET                       
       SYSENTER / SYSEXIT                     
       VIA FEMMS                               

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
         (DEP, NX, EDB)           
          (RNG)         
      PadLock Hash Engine (PHE)                          
      PadLock Montgomery Multiplier (PMM)                
         (PSN)                    

     :
      Automatic Clock Control                            
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                         , 
      Enhanced SpeedStep Technology (EIST, ESS)          
      Frequency ID Control                              
      Hardware P-State Control                           
      LongRun                                            
      LongRun Table Interface                            
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                       
      Software Thermal Control                          
                                               
      Thermal Monitor 1                                  
      Thermal Monitor 2                                  
      Thermal Monitoring                                
      Thermal Trip                                      
      Voltage ID Control                                

     CPUID:
      1 GB Page Size                                     
      36-bit Page Size Extension                        
      Address Region Registers (ARR)                     
      Core Power Boost                                   
      CPL Qualified Debug Store                          
      Debug Trace Store                                  
      Debugging Extension                               
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Fast Save & Restore                               
      Hyper-Threading Technology (HTT)                   
      Invariant Time Stamp Counter                       
      L1 Context ID                                      
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      Nested Paging                                      
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event                                
      Physical Address Extension (PAE)                  
      Safer Mode Extensions (SMX)                        
      Secure Virtual Machine Extensions (Pacifica)      
      Self-Snoop                                         
      Time Stamp Counter (TSC)                          
      Turbo Boost                                        
      Virtual Machine Extensions (Vanderpool)            
      Virtual Mode Extension                            
      x2APIC                                             
      XGETBV / XSETBV OS Enabled                         
      XSAVE / XRSTOR / XSETBV / XGETBV Extended States   

    CPUID Registers (CPU #1):
      CPUID 00000000                                    00000001-68747541-444D4163-69746E65
      CPUID 00000001                                    00060FB1-00020800-00002001-178BFBFF
      CPUID 80000000                                    80000018-68747541-444D4163-69746E65
      CPUID 80000001                                    00060FB1-000008D9-0000011F-EBD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-3620296D
      CPUID 80000003                                    32582034-61754420-6F43206C-50206572
      CPUID 80000004                                    65636F72-726F7373-30303520-00002B30
      CPUID 80000005                                    FF08FF08-FF20FF20-40020140-40020140
      CPUID 80000006                                    00000000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-0000007F
      CPUID 80000008                                    00003028-00000000-00000001-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-00000002
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    00000001-68747541-444D4163-69746E65
      CPUID 00000001                                    00060FB1-01020800-00002001-178BFBFF
      CPUID 80000000                                    80000018-68747541-444D4163-69746E65
      CPUID 80000001                                    00060FB1-000008D9-0000011F-EBD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-3620296D
      CPUID 80000003                                    32582034-61754420-6F43206C-50206572
      CPUID 80000004                                    65636F72-726F7373-30303520-00002B30
      CPUID 80000005                                    FF08FF08-FF20FF20-40020140-40020140
      CPUID 80000006                                    00000000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-0000007F
      CPUID 80000008                                    00003028-00000000-00000001-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-00000002
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000

    MSR Registers:
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR C0010015                                      0000-0000-0200-0048
      MSR C0010042                                      3107-1209-0712-0212
      MSR C0010055                                      0000-0000-0000-0000


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  63-0803-000001-00101111-091307-MCP61$A0626000_BIOS DATE: 09/13/07 11:13:56 VER: 08.00.12
                                          Asus M2N

      FSB:
                                                 AMD Hammer
                                         200 
                                      200 
       HyperTransport                            1000 

      :
                                                 Dual DDR2 SDRAM
                                              128 
       DRAM:FSB                              CPU/7
                                         373  (DDR)
                                      746 
                                   11940 /

        :
                                         1 Socket AM2
                                       3 PCI, 2 PCI-E x1, 1 PCI-E x16
                                              4 DDR2 DIMM
                                    Audio, Gigabit LAN
      -                                       ATX
                                   210 mm x 300 mm
                                    nForce6100-430
                                   JumperFree, Q-Fan 2, Stepless Freq Selection

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/ProductGroup2.aspx?PG_ID=mKyCKlQ4oSEtSu5m
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates
       BIOS                                   http://www.aida64.com/bios-updates


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   4095 
                                                  1246 
                                                2849 
                                                30 %

       :
                                                   8188 
                                                  1379 
                                                6809 
                                                17 %

     :
                                                   12284 
                                                  2626 
                                                9658 
                                                21 %

     :
                                            C:\pagefile.sys
                                           4095 
      /                           57  / 62 
                                                1 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[ SPD ]---------------------------------------------------------------------------------------------------------

  [ DIMM1: 2  DDR2-800 DDR2 SDRAM ]

      :
                                           
                                            2  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          6-6-6-18  (CL-RCD-RP-RAS) / 24-42-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 333                                          5-5-5-15  (CL-RCD-RP-RAS) / 20-35-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

  [ DIMM2: 2  DDR2-800 DDR2 SDRAM ]

      :
                                           
                                            2  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          6-6-6-18  (CL-RCD-RP-RAS) / 24-51-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 333                                          5-5-5-15  (CL-RCD-RP-RAS) / 20-43-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          4-4-4-12  (CL-RCD-RP-RAS) / 16-34-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       


--------[  ]------------------------------------------------------------------------------------------------------

  [  : AMD Hammer DDR2 IMC ]

      :
                                            AMD Hammer DDR2 IMC
                                DDR2-400, DDR2-533, DDR2-667, DDR2-800 SDRAM
                                                  00

     :
                                                     Dual Channel  (128 )
                                           Dual Channel  (128 )

     :
      CAS Latency (CL)                                  6T
      RAS To CAS Delay (tRCD)                           6T
      RAS Precharge (tRP)                               6T
      RAS Active Time (tRAS)                            18T
      Row Cycle Time (tRC)                              26T
      Command Rate (CR)                                 2T
      RAS To RAS Delay (tRRD)                           5T
      Write Recovery Time (tWR)                         6T
      Write To Read Delay (tWTR)                        3T
      Read To Precharge Delay (tRTP)                    4T
      Four Activate Window Delay (tFAW)                 18T
      Refresh Period (tREF)                             7.8 us
      DRAM Drive Strength                               1.0x
      DRAM Data Drive Strength                          1.0x
      Clock Drive Strength                              1.5x
      CKE Drive Strength                                1.5x
      Max Async Latency                                 6 ns
      Idle Cycle Limit                                  16
      Dynamic Idle Cycle Counter                        
      Read/Write Queue Bypass                           8

     :
      ECC                                               , 
      ChipKill ECC                                      , 
      RAID                                               
      DRAM Scrub Rate                                   
      L1 Data Cache Scrub Rate                          
      L2 Cache Scrub Rate                               

     :
       DRAM #1                                    2   (DDR2-800 DDR2 SDRAM)
       DRAM #2                                    2   (DDR2-800 DDR2 SDRAM)

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/DevelopWithAMD/0,,30_2252_873,00.html
                                       http://www.amd.com/us-en/Processors/TechnicalResources/0,,30_182_871_2336,00.html
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [  : nVIDIA nForce 6100-430 (MCP61P) ]

      :
                                               nVIDIA nForce 6100-430 (MCP61P)
                                                  A2
                                  90 nm
      nVIDIA SLI                                         
      nVIDIA Hybrid SLI                                  

      :
                              nVIDIA nForce 6100-430
                           

     PCI Express:
      PCI-E 1.0 x16 port #0                              @ x16  (ATI Radeon HD 5570 (Redwood) Video Adapter, ATI Redwood/Madison - High Definition Audio Controller)
      PCI-E 1.0 x1 port #1                               @ x1
      PCI-E 1.0 x1 port #2                               @ x1

     :
      CPU FSB                                           200.9 
      HyperTransport                                    1004.6 
      PCI Express                                       100.9 
      MAC PHY                                           125.0 
      SATA PHY                                          100.0 
       USB2                                   48.0 
      PIT / ACPI Timer                                  14.3 

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          AMI
       BIOS                                       0803
       AGESA                                      2.8.7.0
        BIOS                               09/13/07
       BIOS                            07/16/10

     BIOS (ATK):

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                   http://www.aida64.com/bios-updates


--------[ ACPI ]--------------------------------------------------------------------------------------------------------

  [ APIC: Multiple APIC Description Table ]

      ACPI:
       ACPI                                      APIC
                                         Multiple APIC Description Table
                                             BFFC0390h
                                           112 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMAPIC
      OEM Revision                                      09000713h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      Local APIC Address                                FEE00000h

  [ DSDT: Differentiated System Description Table ]

      ACPI:
       ACPI                                      DSDT
                                         Differentiated System Description Table
                                             BFFC0440h
                                           21128 
      OEM ID                                            A0626
      OEM Table ID                                      A0626000
      OEM Revision                                      00000000h
      Creator ID                                        INTL
      Creator Revision                                  02002026h

    nVIDIA SLI:
      SLI Certification                                 
      PCI 0-0-0-0 (Direct I/O)                          10DE-03EA
      PCI 0-0-0-0 (HAL)                                 10DE-03EA

  [ FACP: Fixed ACPI Description Table ]

      ACPI:
       ACPI                                      FACP
                                         Fixed ACPI Description Table
                                             BFFC0200h
                                           132 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMFACP
      OEM Revision                                      09000713h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      SMI Command Port                                  0000082Eh
      PM Timer                                          00000508h

  [ FACS: Firmware ACPI Control Structure ]

      ACPI:
       ACPI                                      FACS
                                         Firmware ACPI Control Structure
                                             BFFCE000h
                                           64 

  [ HPET: IA-PC High Precision Event Timer Table ]

      ACPI:
       ACPI                                      HPET
                                         IA-PC High Precision Event Timer Table
                                             BFFC56D0h
                                           56 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMHPET0
      OEM Revision                                      09000713h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ MCFG: Memory Mapped Configuration Space Base Address Description Table ]

      ACPI:
       ACPI                                      MCFG
                                         Memory Mapped Configuration Space Base Address Description Table
                                             BFFC0400h
                                           60 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMMCFG
      OEM Revision                                      09000713h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ OEMB: OEM Specific Information Table ]

      ACPI:
       ACPI                                      OEMB
                                         OEM Specific Information Table
                                             BFFCE040h
                                           96 
      OEM ID                                            A_M_I_
      OEM Table ID                                      AMI_OEM
      OEM Revision                                      09000713h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ RSD PTR: Root System Description Pointer ]

      ACPI:
       ACPI                                      RSD PTR
                                         Root System Description Pointer
                                             000FB810h
                                           20 
      OEM ID                                            ACPIAM
      RSDP Revision                                     0
      RSDT Address                                      BFFC0000h

  [ RSDT: Root System Description Table ]

      ACPI:
       ACPI                                      RSDT
                                         Root System Description Table
                                             BFFC0000h
                                           60 
      OEM ID                                            A_M_I_
      OEM Table ID                                      OEMRSDT
      OEM Revision                                      09000713h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      RSDT Entry #0                                     BFFC0200h
      RSDT Entry #1                                     BFFC0390h
      RSDT Entry #2                                     BFFC0400h
      RSDT Entry #3                                     BFFCE040h
      RSDT Entry #4                                     BFFC56D0h
      RSDT Entry #5                                     BFFC5710h

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             BFFC5710h
                                           650 
      OEM ID                                            A_M_I_
      OEM Table ID                                      POWERNOW
      OEM Revision                                      00000001h
      Creator ID                                        AMD
      Creator Revision                                  00000001h


--------[  Windows ]------------------------------------------------------------------------------------------------

  [   NVIDIA nForce ]

      :
                                            NVIDIA nForce
                                           Ethernet
                                         00-1F-C6-C3-30-E5
                                                 
                                      100 Mbps
      MTU                                               1500 
      DHCP-                               22.02.2012 14:32:09
      DHCP-                               23.02.2012 14:32:09
                                            119590588 (114.1 )
                                          6789463 (6.5 )

      :
       IP /                                 192.168.1.3 / 255.255.255.0
                                                    192.168.1.1
      DHCP                                              192.168.1.1
      DNS                                               192.168.1.1


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    nVIDIA nForce 6100-400/405/420/430 (MCP61) - LAN Controller (PHY: Attansic PHY)   PCI


--------[ IAM ]---------------------------------------------------------------------------------------------------------

  [ Microsoft Communities ]

      :
                                        Microsoft Communities
      ID                                   account{54950F85-CE00-4E35-81C4-F4F3C68EED91}.oeaccount
                                         ( )
                                                (IE  )
      NNTP-                                       msnews.microsoft.com

      :
        NNTP                                
        NNTP                     
        NNTP                        
         NNTP             
       NNTP                
       NNTP   HTML                         

  [ Active Directory ]

      :
                                        Active Directory
      ID                                   account{6C255CF1-E726-4C99-B555-00350541F554}.oeaccount
                                        LDAP
                                                (IE  )
      LDAP-                                       NULL:3268
        LDAP                             NULL
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     

  [    VeriSign ]

      :
                                           VeriSign
      ID                                   account{64BD25E5-C608-44EA-87B5-31C608E9A9CC}.oeaccount
                                        LDAP
                                                (IE  )
      LDAP-                                       directory.verisign.com
      LDAP URL                                          http://www.verisign.com
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        http://go.microsoft.com/fwlink/?LinkId=69157
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                               C:\Users\\Downloads

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.1.1  20   192.168.1.3 (⥢ ஫ NVIDIA nForce)
                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                127.0.0.1  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
              192.168.1.0    255.255.255.0      192.168.1.3  276  192.168.1.3 (⥢ ஫ NVIDIA nForce)
              192.168.1.3  255.255.255.255      192.168.1.3  276  192.168.1.3 (⥢ ஫ NVIDIA nForce)
            192.168.1.255  255.255.255.255      192.168.1.3  276  192.168.1.3 (⥢ ஫ NVIDIA nForce)
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                224.0.0.0        240.0.0.0      192.168.1.3  276  192.168.1.3 (⥢ ஫ NVIDIA nForce)
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255      192.168.1.3  276  192.168.1.3 (⥢ ஫ NVIDIA nForce)


--------[ IE Cookie ]---------------------------------------------------------------------------------------------------

    2012-02-20 16:47:04  @program.avast.com/api/
    2012-02-20 16:47:05  @program.avast.com/
    2012-02-20 19:31:30  @onlinestores.metaservices.microsoft.com/serviceswitching/
    2012-02-22 16:09:47  @sonikelf.com/


--------[   ]--------------------------------------------------------------------------------------------

    2012-02-20 15:11:39  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.bing.com/search?q=system+service+ex&src=IE-SearchBox&FORM=IE8SRC
    2012-02-20 15:11:39  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.bing.com/search?q=system+service+ex&src=IE-SearchBox&FORM=IE8SRC&format=rss
    2012-02-20 15:14:38  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://programmersforum.ru/showthread.php?s=a5523b6e4ae63379820f5464f19238b8&t=107349&page=2
    2012-02-20 15:14:44  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://programmersforum.ru/external.php?type=RSS2
    2012-02-20 15:14:44  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://programmersforum.ru/external.php?type=RSS2&forumids=34
    2012-02-20 15:14:44  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://programmersforum.ru/showthread.php?p=615322
    2012-02-20 15:14:48  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://forum.oszone.net/external.php?type=RSS1
    2012-02-20 15:14:48  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://forum.oszone.net/external.php?type=RSS1&forumids=73
    2012-02-20 15:14:52  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://forum.oszone.net/thread-59513-9.html
    2012-02-20 15:16:10  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.bing.com/search?q=system+service+exception+%D1%87%D1%82%D0%BE+%D1%8D%D1%82%D0%BE&src=IE-SearchBox&FORM=IE8SRC
    2012-02-20 15:16:10  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.bing.com/search?q=system+service+exception+%u0447%u0442%u043e+%u044d%u0442%u043e&src=IE-SearchBox&FORM=IE8SRC&format=rss
    2012-02-20 15:16:15  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/zabroshennye/4134-system_service_exception-0x0000003b.html
    2012-02-20 15:20:08  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/register.php
    2012-02-20 15:22:27  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.mail.ru
    2012-02-20 15:22:45  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://e.mail.ru/cgi-bin/login?email=inferum@mail.ru&fail=1
    2012-02-20 15:23:05  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/register.php?a=act&u=19706&i=08706281b47940d960bdb8a03a23a188c3fa01b1
    2012-02-20 15:23:12  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://e.mail.ru/cgi-bin/msglist?back=1
    2012-02-20 15:23:15  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/register.php?do=addmember
    2012-02-20 15:24:59  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Desktop/022012-25615-01.dmp
    2012-02-20 15:36:37  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.bing.com/search?q=www.firefox.ru&src=IE-SearchBox&FORM=IE8SRC
    2012-02-20 15:36:37  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.bing.com/search?q=www.firefox.ru&src=IE-SearchBox&FORM=IE8SRC&format=rss
    2012-02-20 15:36:53  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.mozilla.org/en-US/firefox/all.html
    2012-02-20 15:37:03  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.mozilla.org/ru/firefox/central
    2012-02-20 15:37:44  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://otvety.google.ru/otvety/rss_v2_0_msgs.xml?tid=3e074f145bfc833f
    2012-02-20 15:38:08  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.google.ru/search?complete=1&hl=ru&newwindow=1&q=64+bit+soft&btnG=%D0%9F%D0%BE%D0%B8%D1%81%D0%BA&lr=&aq=5&oq=64
    2012-02-20 15:38:20  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.64xsoft.com
    2012-02-20 15:38:29  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.64xsoft.com/feed.php?id=11
    2012-02-20 15:38:30  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.64xsoft.com/Internet-Network-Software
    2012-02-20 15:38:36  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.64xsoft.com/feed.php?id=18
    2012-02-20 15:38:36  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.64xsoft.com/feed.php?list=
    2012-02-20 15:38:37  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.64xsoft.com/Internet-Network-Software/Browsers
    2012-02-20 15:39:19  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://x64.divl.ru
    2012-02-20 15:39:20  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://x64.divl.ru/favicon.ico
    2012-02-20 15:39:33  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.start64.com/index.php?format=feed&type=atom
    2012-02-20 15:39:33  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.start64.com/index.php?format=feed&type=rss
    2012-02-20 15:39:35  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.start64.com
    2012-02-20 15:39:44  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.start64.com/index.php?option=com_tag&task=tag&tag=firefox
    2012-02-20 15:39:59  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://otvety.google.ru/otvety/thread?tid=3e074f145bfc833f
    2012-02-20 15:40:03  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.mozilla.org
    2012-02-20 15:40:11  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.google.com/cse?cx=002443141534113389537%3Aysdmevkkknw&cof=FORID%3A0&q=64+bit&x=40&y=11
    2012-02-20 15:40:22  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://armenzg.blogspot.com/feeds/1404806384717284144/comments/default
    2012-02-20 15:40:22  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://armenzg.blogspot.com/feeds/posts/default
    2012-02-20 15:40:22  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://armenzg.blogspot.com/feeds/posts/default?alt=rss
    2012-02-20 15:41:24  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://armenzg.blogspot.com/2010/05/pre-release-firefox-windows-64-bit.html
    2012-02-20 15:41:27  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://habrahabr.ru/blogs/browsers/95311
    2012-02-20 15:41:27  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://habrahabr.ru/rss/post/95311
    2012-02-20 15:41:54  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://zone-pc.ru/index.php/feed
    2012-02-20 15:41:54  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://zone-pc.ru/index.php/feed/atom
    2012-02-20 15:41:54  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://zone-pc.ru/index.php/soft/firefox-4-0-x64-64-bit-dlya-windows-7-i-vista/feed
    2012-02-20 15:43:28  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://letitbit.net/download/33585.3386a261b4de0be600b24f233/firefox_3.7a5pre.en_US.win64_x86_64.installer.exe.html
    2012-02-20 15:43:28  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://zone-pc.ru/index.php/soft/firefox-4-0-x64-64-bit-dlya-windows-7-i-vista
    2012-02-20 15:43:36  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://rubezhnoe.org.ua/load/mozilla_firefox_3_6_3_64_bit/48-1-0-778
    2012-02-20 15:44:23  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://wiki.mozilla-x86-64.com/images/Firefox-3.6.3.en-US.win64-x86_64.installer.zip
    2012-02-20 15:44:26  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.tehnari.ru/f180/t37308
    2012-02-20 15:45:07  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.tehnari.ru/favicon.ico
    2012-02-20 15:45:16  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Downloads/Firefox-3.6.3.en-US.win64-x86_64.installer.zip
    2012-02-20 15:50:01  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.tehnari.ru/f180/t37308/index2.html
    2012-02-20 15:50:55  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://mirsofta.su/comments/feed
    2012-02-20 15:50:55  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://mirsofta.su/feed
    2012-02-20 15:50:56  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://mirsofta.su/safari/357
    2012-02-20 15:50:57  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://mirsofta.su/safari/357/favicon.ico
    2012-02-20 15:51:24  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://soft.softodrom.ru/ap/Apple-Safari-p4300
    2012-02-20 15:51:42  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://soft.softodrom.ru/%D0%A1%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C/4300
    2012-02-20 15:51:42  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://soft.softodrom.ru//4300
    2012-02-20 15:52:11  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://appldnld.apple.com/Safari5/041-3230.20111128.Ju654/SafariSetup.exe
    2012-02-20 15:55:39  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.bing.com/search?q=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+safari+%D0%B4%D0%BB%D1%8F+windows7+64+bit&src=IE-SearchBox&FORM=IE8SRC
    2012-02-20 15:56:00  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://nunahren.ru/prog/inet/121-flash-player-ie-firefox-opera
    2012-02-20 15:56:02  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://ads.depositfiles.com/favicon.ico
    2012-02-20 15:56:03  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://vip-vlub.ru/depo
    2012-02-20 15:56:03  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://vip-vlub.ru/favicon.ico
    2012-02-20 15:56:04  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.vulkancasino.com/?p12997p20269p001ct0
    2012-02-20 15:56:05  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://www.vulkancasino.com/favicon.ico
    2012-02-20 15:56:07  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://depositfiles.com/files/gl3gse592
    2012-02-20 15:58:38  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Downloads/install_flash_player_11_plugin_64bit.exe.zip
    2012-02-20 19:59:48  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Desktop/210049_1024.jpg
    2012-02-20 20:01:55  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Desktop/854002801.jpg
    2012-02-20 20:02:20  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Desktop/reWalls.com-2649.jpg
    2012-02-20 20:03:17  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Desktop/bmw_m5_twin_turbo_wallpaper_1.jpg
    2012-02-22 14:44:27  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/newthread.php?do=newthread&f=41
    2012-02-22 14:44:40  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/newattachment.php
    2012-02-22 14:45:28  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/newthread.php?do=postthread&f=41
    2012-02-22 14:48:11  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/nedooformlennye
    2012-02-22 14:48:20  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/external.php?type=RSS2&forumids=63
    2012-02-22 14:49:19  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/nedooformlennye/6764-raznye-oshibki-no-vezde-vinovat-ntoskrnl-exe.html
    2012-02-22 14:49:19  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/zabroshennye/6769-0x0000003b.html
    2012-02-22 14:53:01  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.ru/faq
    2012-02-22 14:59:23  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/forum.php
    2012-02-22 14:59:48  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/sinij-ekran-smerti
    2012-02-22 15:00:00  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/sinij-ekran-smerti/announcements.html
    2012-02-22 15:52:32  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/usercp.php
    2012-02-22 15:52:36  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://ru.msn.com/?ocid=iehp
    2012-02-22 15:56:05  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.ru/feed
    2012-02-22 15:56:05  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.ru/zhara-ili-vsyo-o-temperaturax
    2012-02-22 15:59:54  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/login.php?do=login
    2012-02-22 16:00:58  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/external.php?type=RSS2&forumids=65
    2012-02-22 16:00:58  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/zabroshennye/7090-pomogite-razobratsya.html
    2012-02-22 16:01:02  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/external.php?type=RSS2
    2012-02-22 16:01:02  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/external.php?type=RSS2&forumids=41
    2012-02-22 16:01:02  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/sinij-ekran-smerti/8104-pomogite-razobratsya.html
    2012-02-22 16:07:25  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Desktop/%D0%90%D1%80%D1%85%D0%B8%D0%B2%20WinRAR.rar
    2012-02-22 16:09:24  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@file:///C:/Users/%D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2/Desktop/022212-16676-01.rar
    2012-02-22 16:17:23  %D0%92%D0%BB%D0%B0%D0%B4%D0%B8%D1%81%D0%BB%D0%B0%D0%B2@http://sonikelf.com/sinij-ekran-smerti/196-pravila-oformleniya-tem.html


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.7601.17514   Final Retail                         70656  21.11.2010 7:24:00
    bdaplgin.ax                               6.01.7600.16385   Final Retail                         74240  14.07.2009 5:14:10
    d3d8.dll                                  6.01.7600.16385   Final Retail                    1036800  14.07.2009 5:15:08
    d3d8thk.dll                               6.01.7600.16385   Final Retail                      11264  14.07.2009 5:15:08
    d3d9.dll                                  6.01.7601.17514   Final Retail                    1828352  21.11.2010 7:24:23
    d3dim.dll                                 6.01.7600.16385   Final Retail                     386048  14.07.2009 5:15:08
    d3dim700.dll                              6.01.7600.16385   Final Retail                     817664  14.07.2009 5:15:08
    d3dramp.dll                               6.01.7600.16385   Final Retail                     593920  14.07.2009 5:15:08
    d3dxof.dll                                6.01.7600.16385   Final Retail                      53760  14.07.2009 5:15:08
    ddraw.dll                                 6.01.7600.16385   Final Retail                        531968  14.07.2009 5:15:10
    ddrawex.dll                               6.01.7600.16385   Final Retail                      30208  14.07.2009 5:15:10
    devenum.dll                               6.06.7600.16385   Final Retail                         66560  14.07.2009 5:15:10
    dinput.dll                                6.01.7600.16385   Final Retail                        136704  14.07.2009 5:15:11
    dinput8.dll                               6.01.7600.16385   Final Retail                        145408  14.07.2009 5:15:11
    dmband.dll                                6.01.7600.16385   Final Retail                      30720  14.07.2009 5:15:12
    dmcompos.dll                              6.01.7600.16385   Final Retail                      63488  14.07.2009 5:15:12
    dmime.dll                                 6.01.7600.16385   Final Retail                     179712  14.07.2009 5:15:12
    dmloader.dll                              6.01.7600.16385   Final Retail                      38400  14.07.2009 5:15:12
    dmscript.dll                              6.01.7600.16385   Final Retail                      86016  14.07.2009 5:15:12
    dmstyle.dll                               6.01.7600.16385   Final Retail                     105984  14.07.2009 5:15:12
    dmsynth.dll                               6.01.7600.16385   Final Retail                     105472  14.07.2009 5:15:12
    dmusic.dll                                6.01.7600.16385   Final Retail                        101376  14.07.2009 5:15:12
    dplaysvr.exe                              6.01.7600.16385   Final Retail                         29184  14.07.2009 5:14:18
    dplayx.dll                                6.01.7600.16385   Final Retail                     213504  14.07.2009 5:15:12
    dpmodemx.dll                              6.01.7600.16385   Final Retail                         23040  14.07.2009 5:15:12
    dpnaddr.dll                               6.01.7601.17514   Final Retail                       2560  21.11.2010 7:23:53
    dpnet.dll                                 6.01.7600.16385   Final Retail                        376832  14.07.2009 5:15:12
    dpnhpast.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 5:15:12
    dpnhupnp.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 5:15:12
    dpnlobby.dll                              6.01.7600.16385   Final Retail                       2560  14.07.2009 5:04:52
    dpnsvr.exe                                6.01.7600.16385   Final Retail                         33280  14.07.2009 5:14:18
    dpwsockx.dll                              6.01.7600.16385   Final Retail                         44032  14.07.2009 5:15:12
    dsdmo.dll                                 6.01.7600.16385   Final Retail                     173568  14.07.2009 5:15:13
    dsound.dll                                6.01.7600.16385   Final Retail                        453632  14.07.2009 5:15:13
    dswave.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 5:15:13
    dxdiagn.dll                               6.01.7601.17514   Final Retail                        210432  21.11.2010 7:24:22
    dxmasf.dll                                12.00.7601.17514  Final Retail                       4096  21.11.2010 7:25:10
    encapi.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 5:15:14
    gcdef.dll                                 6.01.7600.16385   Final Retail                        120832  14.07.2009 5:15:22
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  14.07.2009 5:14:10
    ir41_32.ax                                4.51.0016.0003    Final Retail                        839680  14.07.2009 5:14:10
    ir41_qc.dll                               4.30.0062.0002    Final Retail                     120320  14.07.2009 5:15:34
    ir41_qcx.dll                              4.30.0062.0002    Final Retail                     120320  14.07.2009 5:15:34
    ir50_32.dll                               5.2562.0015.0055  Final Retail                        746496  14.07.2009 5:15:34
    ir50_qc.dll                               5.00.0063.0048    Final Retail                     200192  14.07.2009 5:15:34
    ir50_qcx.dll                              5.00.0063.0048    Final Retail                     200192  14.07.2009 5:15:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  14.07.2009 5:14:10
    joy.cpl                                   6.01.7600.16385   Final Retail                        138240  14.07.2009 5:14:09
    ksproxy.ax                                6.01.7601.17514   Final Retail                        193536  21.11.2010 7:24:32
    kstvtune.ax                               6.01.7601.17514   Final Retail                         84480  21.11.2010 7:25:10
    ksuser.dll                                6.01.7600.16385   Final Retail                          4608  14.07.2009 5:15:35
    kswdmcap.ax                               6.01.7601.17514   Final Retail                        107008  21.11.2010 7:24:15
    ksxbar.ax                                 6.01.7601.17514   Final Retail                         48640  21.11.2010 7:25:10
    mciqtz32.dll                              6.06.7601.17514   Final Retail                         36352  21.11.2010 7:24:00
    mfc40.dll                                 4.01.0000.6151    Beta Retail                         954752  21.11.2010 7:24:00
    mfc42.dll                                 6.06.8063.0000    Beta Retail                        1136640  14.07.2009 5:15:39
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  22.02.2012 15:00:20
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  22.02.2012 15:00:20
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  22.02.2012 15:00:20
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  22.02.2012 15:00:09
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  22.02.2012 15:00:10
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  22.02.2012 15:00:10
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  22.02.2012 15:00:10
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  22.02.2012 15:00:10
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  22.02.2012 15:00:11
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  22.02.2012 15:00:11
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  22.02.2012 15:00:12
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  22.02.2012 15:00:12
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  22.02.2012 15:00:20
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  22.02.2012 15:00:21
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  22.02.2012 15:00:21
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  22.02.2012 15:00:21
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  22.02.2012 15:00:21
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  22.02.2012 15:00:20
    mpeg2data.ax                              6.06.7601.17514   Final Retail                         72704  21.11.2010 7:25:10
    mpg2splt.ax                               6.06.7601.17514   Final Retail                     199680  21.11.2010 7:25:10
    msdmo.dll                                 6.06.7601.17514   Final Retail                      30720  21.11.2010 7:24:02
    msdvbnp.ax                                6.06.7601.17514   Final Retail                         59904  21.11.2010 7:25:10
    msvidctl.dll                              6.05.7601.17514   Final Retail                       2291712  21.11.2010 7:25:10
    msyuv.dll                                 6.01.7601.17514   Final Retail                      22528  21.11.2010 7:23:50
    pid.dll                                   6.01.7600.16385   Final Retail                      36352  14.07.2009 5:16:12
    psisdecd.dll                              6.06.7600.16385   Final Retail                        465408  14.07.2009 5:16:12
    psisrndr.ax                               6.06.7601.17514   Final Retail                         75776  21.11.2010 7:25:10
    qasf.dll                                  12.00.7601.17514  Final Retail                     206848  21.11.2010 7:24:01
    qcap.dll                                  6.06.7601.17514   Final Retail                        190976  21.11.2010 7:24:08
    qdv.dll                                   6.06.7601.17514   Final Retail                        283136  21.11.2010 7:24:09
    qdvd.dll                                  6.06.7601.17514   Final Retail                        514560  21.11.2010 7:23:55
    qedit.dll                                 6.06.7601.17514   Final Retail                        509440  21.11.2010 7:25:10
    qedwipes.dll                              6.06.7600.16385   Final Retail                     733184  14.07.2009 5:09:35
    quartz.dll                                6.06.7601.17514   Final Retail                       1328128  21.11.2010 7:23:56
    vbisurf.ax                                6.01.7601.17514   Final Retail                      33792  21.11.2010 7:25:10
    vfwwdm32.dll                              6.01.7601.17514   Final Retail                         56832  21.11.2010 7:24:09
    wsock32.dll                               6.01.7600.16385   Final Retail                         15360  14.07.2009 5:16:20


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       aticfx32.dll (8.17.10.1036)
                                      ATI Radeon HD 5500 Series

     Direct3D:
                                16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x
                               1 x 1
                              4096 x 4096
                              5.0
        DirectX                      DirectX v11.0

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Compute Shader                                    
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      Directional Lights                                
      DirectX Texture Compression                       
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Double-Precision Floating-Point                    
      Driver Concurrent Creates                         
      Driver Command Lists                               
      Dynamic Textures                                  
      Edge Anti-Aliasing                                 
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Geometry Shader                                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Lights                                      
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Spot Lights                                       
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                   
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      AYUV                                              
      DXT1                                              
      DXT2                                              
      DXT3                                              
      DXT4                                              
      DXT5                                              
      GET4                                              
      INST                                              
      M2IA                                              
      NULL                                              
      NV12                                              
      NV21                                              
      R2VB                                              
      RESZ                                              
      SYV2                                              
      TES1                                              
      TESS                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/Pages/graphics.aspx
                                       http://sites.amd.com/us/game/downloads/Pages/downloads.aspx
                                     http://www.aida64.com/driver-updates


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (C-Media PCI Audio Device) ]

     DirectSound:
                                       (C-Media PCI Audio Device)
                                          {0.0.0.00000000}.{dae20678-4ca4-4030-bff6-dc039e9e365d}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [  ]

     DirectInput:
                                      
                                           
                                        
                                                     3
      /                                    5

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [  ]

     DirectInput:
                                      
                                           
                                        
      /                                    128

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      


--------[  Windows ]------------------------------------------------------------------------------------------

  [  ]

    DVD  CD-ROM :
      Optiarc DVD RW AD-7173A ATA Device                6.1.7601.17514

    IDE ATA/ATAPI :
      ATA Channel 0                                     6.1.7601.17514
      ATA Channel 1                                     6.1.7601.17514
         PCI IDE      6.1.7601.17514

    :
      ATI Radeon HD 5500 Series                         8.753.0.0

      :
                                                6.1.7600.16385

     :
      ADATA NH13 USB Device                             6.1.7600.16385
      SAMSUNG HD120IJ SCSI Disk Device                  6.1.7600.16385

      :
      amdkmdag                                          
      Ancillary Function Driver for Winsock             
      aswRdr                                            
      aswSP                                             
      avast! Network Shield Support                     
      Beep                                              
      CNG                                               
      Hardware Policy Driver                            
      HTTP                                              
      Kernel Mode Driver Frameworks service             
      KSecDD                                            
      KSecPkg                                           
      LDDM Graphics Subsystem                           
      Link-Layer Topology Discovery Mapper I/O Driver   
      Link-Layer Topology Discovery Responder           
      msisadrv                                          
      NDProxy                                           
      NETBT                                             
      NSI proxy service driver.                         
      Null                                              
      PEAUTH                                            
      Performance Counters for Windows Driver           
      RDP Encoder Mirror Driver                         
      RDPCDD                                            
      Reflector Display Driver used to gain access to graphics data
      Security Driver                                   
      Security Processor Loader Driver                  
      System Attribute Cache                            
      TCP/IP Registry Compatibility                     
      VgaSave                                           
      WFP Lightweight Filter                            
            
                              
                               
                                 
         Windows           
        NetIO Legacy TDI                
        TCP/IP                          
         IPv6 ARP               
          Bitlocker        
        (CLFS)                               
        QoS                           
        NDIS                            
                               

    ,    :
      ATI High Definition Audio Device                  7.11.0.7706
      C-Media PCI Audio Device                          6.12.8.1737

    :
        PS/2                       6.1.7601.17514

    :
      ACPI x64-based PC                                 6.1.7600.16385

     USB:
         USB                   6.1.7601.17514
       USB-                         6.1.7601.17514
       USB-                         6.1.7601.17514
       OpenHCD USB -           6.1.7601.17514
        PCI - USB - 6.1.7601.17514

      :
                       6.1.7600.16385

      :
       NVIDIA nForce Serial ATA               10.6.0.19
       NVIDIA nForce Serial ATA               10.6.0.19

    :
        PnP                         6.1.7600.16385

        :
      Microsoft PS/2                                6.1.7600.16385

     (COM  LPT):
        (LPT1)                              6.1.7600.16385
        (COM1)                      6.1.7600.16385

    :
      AMD Athlon(tm) 64 X2 Dual Core Processor 5000+    6.1.7600.16385
      AMD Athlon(tm) 64 X2 Dual Core Processor 5000+    6.1.7600.16385

     :
      Teredo Tunneling Pseudo-Interface                 6.1.7600.16385
      WAN Miniport (IKEv2)                              6.1.7601.17514
       Microsoft ISATAP                          6.1.7600.16385
       WAN (IP)                                 6.1.7601.17514
       WAN (IPv6)                               6.1.7601.17514
       WAN (L2TP)                               6.1.7601.17514
       WAN (PPPoE)                              6.1.7601.17514
       WAN (PPTP)                               6.1.7601.17514
      - WAN (SSTP)                              6.1.7601.17514
       WAN ( )                    6.1.7601.17514
        NVIDIA nForce                  1.0.1.211

     :
      AMD Address Map                       6.1.7601.17514
      AMD DRAM  HyperTransport(tm) Trace Mode 6.1.7601.17514
      AMD HyperTransport(tm)                6.1.7601.17514
      AMD                             6.1.7601.17514
      ATK0110 ACPI UTILITY                              1043.6.0.0
      CMOS                                         6.1.7601.17514
      Microsoft ACPI-                 6.1.7601.17514
      Microsoft System Management BIOS           6.1.7601.17514
      NVIDIA nForce PCI System Management               6.1.7601.17514
      Remote Desktop Device Redirector Bus              6.1.7600.16385
      UMBus                    6.1.7601.17514
      UMBus                                6.1.7601.17514
                               6.1.7601.17514
                                       6.1.7601.17514
                               6.1.7601.17514
                                          6.1.7601.17514
                      6.1.7601.17514
                            6.1.7601.17514
          ()6.1.7601.17514
                               6.1.7600.16385
        ACPI                               6.1.7601.17514
       High Definition Audio (Microsoft)      6.1.7601.17514
                         6.1.7601.17514
                        6.1.7601.17514
                            6.1.7601.17514
         Plug and Play 6.1.7601.17514
                     6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                          6.1.7601.17514
                                         6.1.7601.17514
       PCI- RAM                    6.1.7601.17514
       PCI- RAM                    6.1.7601.17514
        PCI - ISA                        6.1.7601.17514
        PCI - PCI                        6.1.7601.17514
        PCI - PCI                        6.1.7601.17514
        PCI - PCI                        6.1.7601.17514
        PCI - PCI                        6.1.7601.17514
         ACPI          6.1.7601.17514
       PCI                                          6.1.7601.17514

        :
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385

      :
                                        6.1.7601.17514
                                        6.1.7601.17514

      :
      FaceCam 300                                       1.0.0.28

  [ DVD  CD-ROM  / Optiarc DVD RW AD-7173A ATA Device ]

     :
                                        Optiarc DVD RW AD-7173A ATA Device
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          cdrom.inf
       ID                                     IDE\CdRomOptiarc_DVD_RW_AD-7173A_________________1-04____
                                     Channel 0, Target 0, Lun 0

     :
                                                   Sony NEC Optiarc Inc.
                                     http://www.sonynec-optiarc.com/products/index.html
       firmware                                 http://www.sonynec-optiarc.com
                                     http://www.aida64.com/driver-updates

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     10de-03ec
                                     Channel 0

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     10de-03ec
                                     Channel 1

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [ IDE ATA/ATAPI  /    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     PCI\VEN_10DE&DEV_03EC&SUBSYS_82341043&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,6,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - Parallel ATA Controller

     :
                                                    FFA0-FFAF

  [  / ATI Radeon HD 5500 Series ]

     :
                                        ATI Radeon HD 5500 Series
                                            06.07.2010
                                          8.753.0.0
                                       ATI Technologies Inc.
      INF-                                          oem5.inf
       ID                                     PCI\VEN_1002&DEV_68D9&SUBSYS_036C1043&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(2,0,0)
      PCI-                                    ATI Radeon HD 5570 (Redwood) Video Adapter

     :
      IRQ                                               65536
                                                  000A0000-000BFFFF
                                                  C0000000-CFFFFFFF
                                                  DFFE0000-DFFFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    E800-E8FF

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/Pages/graphics.aspx
                                       http://sites.amd.com/us/game/downloads/Pages/downloads.aspx
                                     http://www.aida64.com/driver-updates

  [    /  ]

     :
                                        
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          flpydisk.inf
       ID                                     FDC\GENERIC_FLOPPY_DRIVE

  [   / ADATA NH13 USB Device ]

     :
                                        ADATA NH13 USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     USBSTOR\DiskADATA___NH13____________GN00

     :
                                                   ADATA Technology Co.
                                     http://www.adata.com.tw/index.php?action=product&cid=3
                                     http://www.aida64.com/driver-updates

  [   / SAMSUNG HD120IJ SCSI Disk Device ]

     :
                                        SAMSUNG HD120IJ SCSI Disk Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     SCSI\DiskSAMSUNG_HD120IJ_________ZL10
                                     Bus Number 0, Target Id 0, LUN 0

     :
                                                   Samsung
                                     http://www.samsung.com/global/business/hdd
                                     http://www.aida64.com/driver-updates

  [    / amdkmdag ]

     :
                                        amdkmdag

  [    / Ancillary Function Driver for Winsock ]

     :
                                        Ancillary Function Driver for Winsock

  [    / aswRdr ]

     :
                                        aswRdr

  [    / aswSP ]

     :
                                        aswSP

  [    / avast! Network Shield Support ]

     :
                                        avast! Network Shield Support

  [    / Beep ]

     :
                                        Beep

  [    / CNG ]

     :
                                        CNG

  [    / Hardware Policy Driver ]

     :
                                        Hardware Policy Driver

  [    / HTTP ]

     :
                                        HTTP

  [    / Kernel Mode Driver Frameworks service ]

     :
                                        Kernel Mode Driver Frameworks service

  [    / KSecDD ]

     :
                                        KSecDD

  [    / KSecPkg ]

     :
                                        KSecPkg

  [    / LDDM Graphics Subsystem ]

     :
                                        LDDM Graphics Subsystem

  [    / Link-Layer Topology Discovery Mapper I/O Driver ]

     :
                                        Link-Layer Topology Discovery Mapper I/O Driver

  [    / Link-Layer Topology Discovery Responder ]

     :
                                        Link-Layer Topology Discovery Responder

  [    / msisadrv ]

     :
                                        msisadrv

  [    / NDProxy ]

     :
                                        NDProxy

  [    / NETBT ]

     :
                                        NETBT

  [    / NSI proxy service driver. ]

     :
                                        NSI proxy service driver.

  [    / Null ]

     :
                                        Null

  [    / PEAUTH ]

     :
                                        PEAUTH

  [    / Performance Counters for Windows Driver ]

     :
                                        Performance Counters for Windows Driver

  [    / RDP Encoder Mirror Driver ]

     :
                                        RDP Encoder Mirror Driver

  [    / RDPCDD ]

     :
                                        RDPCDD

  [    / Reflector Display Driver used to gain access to graphics data ]

     :
                                        Reflector Display Driver used to gain access to graphics data

  [    / Security Driver ]

     :
                                        Security Driver

  [    / Security Processor Loader Driver ]

     :
                                        Security Processor Loader Driver

  [    / System Attribute Cache ]

     :
                                        System Attribute Cache

  [    / TCP/IP Registry Compatibility ]

     :
                                        TCP/IP Registry Compatibility

  [    / VgaSave ]

     :
                                        VgaSave

  [    / WFP Lightweight Filter ]

     :
                                        WFP Lightweight Filter

  [    /        ]

     :
                                              

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /    Windows ]

     :
                                           Windows

  [    /   NetIO Legacy TDI ]

     :
                                          NetIO Legacy TDI

  [    /   TCP/IP ]

     :
                                          TCP/IP

  [    /    IPv6 ARP ]

     :
                                           IPv6 ARP

  [    /     Bitlocker ]

     :
                                            Bitlocker

  [    /   (CLFS) ]

     :
                                          (CLFS)

  [    /   QoS ]

     :
                                          QoS

  [    /   NDIS ]

     :
                                          NDIS

  [    /    ]

     :
                                          

  [ ,     / ATI High Definition Audio Device ]

     :
                                        ATI High Definition Audio Device
                                            06.05.2010
                                          7.11.0.7706
                                       ATI Technologies Inc.
      INF-                                          oem6.inf
       ID                                     HDAUDIO\FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1002
                                       High Definition Audio

     :
                                                   Advanced Micro Devices, Inc.
                                     http://ati.amd.com/products/integrated.html
                                       http://ati.amd.com/support/driver.html
                                     http://www.aida64.com/driver-updates

  [ ,     / C-Media PCI Audio Device ]

     :
                                        C-Media PCI Audio Device
                                            19.05.2009
                                          6.12.8.1737
                                       C-Media Electronics Inc.
      INF-                                          oem3.inf
       ID                                     PCI\VEN_13F6&DEV_0111&SUBSYS_011113F6&REV_10
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(1,8,0)
      PCI-                                    C-Media CMI8738/C3DX Audio Device

     :
      IRQ                                               17
                                                    D800-D8FF

     :
                                                   C-Media Electronics, Inc.
                                     http://www.cmedia.com.tw/?q=en/products
                                       http://www.cmedia.com.tw/?q=en/cm_drivers
                                     http://www.aida64.com/driver-updates

  [  /   PS/2 ]

     :
                                          PS/2
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          keyboard.inf
       ID                                     ACPI\PNP0303
      PnP-                                    101/102-Key or MS Natural Keyboard

     :
      IRQ                                               01
                                                    0060-0060
                                                    0064-0064

  [  / ACPI x64-based PC ]

     :
                                        ACPI x64-based PC
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hal.inf
       ID                                     acpiapic

  [  USB /    USB ]

     :
                                           USB
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbstor.inf
       ID                                     USB\VID_125F&PID_A13A&REV_0100
                                     Port_#0004.Hub_#0002

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID10DE&PID03F1&REV00A3

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID10DE&PID03F2&REV00A3

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_10DE&DEV_03F1&SUBSYS_82341043&REV_A3
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,2,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - OHCI USB 1.1 Controller

     :
      IRQ                                               23
                                                  DFEFF000-DFEFFFFF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_10DE&DEV_03F2&SUBSYS_82341043&REV_A3
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,2,1)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - EHCI USB 2.0 Controller

     :
      IRQ                                               22
                                                  DFEFEC00-DFEFECFF

  [    /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          fdc.inf
       ID                                     ACPI\PNP0700
      PnP-                                    Floppy Disk Controller

     :
      DMA                                               02
      IRQ                                               06
                                                    03F0-03F5
                                                    03F7-03F7

  [    /  NVIDIA nForce Serial ATA ]

     :
                                         NVIDIA nForce Serial ATA
                                            06.08.2010
                                          10.6.0.19
                                       NVIDIA Corporation
      INF-                                          nvraid.inf
       ID                                     PCI\VEN_10DE&DEV_03F6&SUBSYS_82341043&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,8,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller

     :
      IRQ                                               20
                                                  DFEFC000-DFEFCFFF
                                                    B880-B88F
                                                    BC00-BC03
                                                    C000-C007
                                                    C080-C083
                                                    C400-C407

  [    /  NVIDIA nForce Serial ATA ]

     :
                                         NVIDIA nForce Serial ATA
                                            06.08.2010
                                          10.6.0.19
                                       NVIDIA Corporation
      INF-                                          nvraid.inf
       ID                                     PCI\VEN_10DE&DEV_03F6&SUBSYS_82341043&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,8,1)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller

     :
      IRQ                                               21
                                                  DFEF7000-DFEF7FFF
                                                    B000-B00F
                                                    B080-B083
                                                    B400-B407
                                                    B480-B483
                                                    B800-B807

  [  /   PnP ]

     :
                                          PnP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          monitor.inf
       ID                                     MONITOR\SAM022B
                                                 Samsung SyncMaster 720N

     :
                                                   Samsung
                                     http://www.samsung.com/us/computer/monitors
                                       http://www.samsung.com/us/support
                                     http://www.aida64.com/driver-updates

  [      / Microsoft PS/2  ]

     :
                                        Microsoft PS/2 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msmouse.inf
       ID                                     ACPI\PNP0F03
      PnP-                                    Microsoft PS/2 Port Mouse

     :
      IRQ                                               12

     :
                                                   Microsoft Corporation
                                     http://www.microsoft.com/products
                                       http://www.microsoft.com/downloads
                                     http://www.aida64.com/driver-updates

  [  (COM  LPT) /   (LPT1) ]

     :
                                          (LPT1)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msports.inf
       ID                                     ACPI\PNP0400
      PnP-                                    Parallel Port

     :
                                                    0378-037F

  [  (COM  LPT) /   (COM1) ]

     :
                                          (COM1)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msports.inf
       ID                                     ACPI\PNP0501
      PnP-                                    16550A-compatible UART Serial Port

     :
      IRQ                                               04
                                                    03F8-03FF

  [  / AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ ]

     :
                                        AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_15_Model_107

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

  [  / AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ ]

     :
                                        AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_AMD64_Family_15_Model_107

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

  [   / Teredo Tunneling Pseudo-Interface ]

     :
                                        Teredo Tunneling Pseudo-Interface
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *TEREDO

  [   / WAN Miniport (IKEv2) ]

     :
                                        WAN Miniport (IKEv2)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netavpna.inf
       ID                                     ms_agilevpnminiport

  [   /  Microsoft ISATAP ]

     :
                                         Microsoft ISATAP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  WAN (IP) ]

     :
                                        WAN Miniport (IP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanip

  [   /  WAN (IPv6) ]

     :
                                        WAN Miniport (IPv6)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanipv6

  [   /  WAN (L2TP) ]

     :
                                        WAN Miniport (L2TP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_l2tpminiport

  [   /  WAN (PPPoE) ]

     :
                                        WAN Miniport (PPPOE)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_pppoeminiport

  [   /  WAN (PPTP) ]

     :
                                        WAN Miniport (PPTP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_pptpminiport

  [   / - WAN (SSTP) ]

     :
                                        WAN Miniport (SSTP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netsstpa.inf
       ID                                     ms_sstpminiport

  [   /  WAN ( ) ]

     :
                                        WAN Miniport (Network Monitor)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanbh

  [   /   NVIDIA nForce ]

     :
                                          NVIDIA nForce
                                            17.10.2008
                                          1.0.1.211
                                       Microsoft
      INF-                                          netnvm64.inf
       ID                                     PCI\VEN_10DE&DEV_03EF&SUBSYS_82341043&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,7,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - LAN Controller

     :
      IRQ                                               20
                                                  DFEFD000-DFEFDFFF

      :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [   / AMD Address Map  ]

     :
                                        AMD Address Map 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1101&SUBSYS_00000000&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,1)
      PCI-                                    AMD Hammer - Address Map

  [   / AMD DRAM  HyperTransport(tm) Trace Mode  ]

     :
                                        AMD DRAM  HyperTransport(tm) Trace Mode 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1102&SUBSYS_00000000&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,2)
      PCI-                                    AMD Hammer - DRAM Controller

  [   / AMD HyperTransport(tm)  ]

     :
                                        AMD HyperTransport(tm) 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1100&SUBSYS_00000000&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,0)
      PCI-                                    AMD Hammer - HyperTransport Technology Configuration

  [   / AMD   ]

     :
                                        AMD  
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1103&SUBSYS_00000000&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,3)
      PCI-                                    AMD Hammer - Miscellaneous Control

  [   / ATK0110 ACPI UTILITY ]

     :
                                        ATK0110 ACPI UTILITY
                                            16.07.2009
                                          1043.6.0.0
                                       ATK
      INF-                                          oem4.inf
       ID                                     ACPI\ATK0110
      PnP-                                    Asus ATK-110 ACPI Utility

  [   / CMOS   ]

     :
                                        CMOS  
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0B00
      PnP-                                    Real-Time Clock

     :
      IRQ                                               08
                                                    0070-0071

  [   / Microsoft ACPI-  ]

     :
                                        Microsoft ACPI- 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          acpi.inf
       ID                                     ACPI_HAL\PNP0C08
      PnP-                                    ACPI Driver/BIOS

     :
      IRQ                                               100
      IRQ                                               101
      IRQ                                               102
      IRQ                                               103
      IRQ                                               104
      IRQ                                               105
      IRQ                                               106
      IRQ                                               107
      IRQ                                               108
      IRQ                                               109
      IRQ                                               110
      IRQ                                               111
      IRQ                                               112
      IRQ                                               113
      IRQ                                               114
      IRQ                                               115
      IRQ                                               116
      IRQ                                               117
      IRQ                                               118
      IRQ                                               119
      IRQ                                               120
      IRQ                                               121
      IRQ                                               122
      IRQ                                               123
      IRQ                                               124
      IRQ                                               125
      IRQ                                               126
      IRQ                                               127
      IRQ                                               128
      IRQ                                               129
      IRQ                                               130
      IRQ                                               131
      IRQ                                               132
      IRQ                                               133
      IRQ                                               134
      IRQ                                               135
      IRQ                                               136
      IRQ                                               137
      IRQ                                               138
      IRQ                                               139
      IRQ                                               140
      IRQ                                               141
      IRQ                                               142
      IRQ                                               143
      IRQ                                               144
      IRQ                                               145
      IRQ                                               146
      IRQ                                               147
      IRQ                                               148
      IRQ                                               149
      IRQ                                               150
      IRQ                                               151
      IRQ                                               152
      IRQ                                               153
      IRQ                                               154
      IRQ                                               155
      IRQ                                               156
      IRQ                                               157
      IRQ                                               158
      IRQ                                               159
      IRQ                                               160
      IRQ                                               161
      IRQ                                               162
      IRQ                                               163
      IRQ                                               164
      IRQ                                               165
      IRQ                                               166
      IRQ                                               167
      IRQ                                               168
      IRQ                                               169
      IRQ                                               170
      IRQ                                               171
      IRQ                                               172
      IRQ                                               173
      IRQ                                               174
      IRQ                                               175
      IRQ                                               176
      IRQ                                               177
      IRQ                                               178
      IRQ                                               179
      IRQ                                               180
      IRQ                                               181
      IRQ                                               182
      IRQ                                               183
      IRQ                                               184
      IRQ                                               185
      IRQ                                               186
      IRQ                                               187
      IRQ                                               188
      IRQ                                               189
      IRQ                                               190
      IRQ                                               81
      IRQ                                               82
      IRQ                                               83
      IRQ                                               84
      IRQ                                               85
      IRQ                                               86
      IRQ                                               87
      IRQ                                               88
      IRQ                                               89
      IRQ                                               90
      IRQ                                               91
      IRQ                                               92
      IRQ                                               93
      IRQ                                               94
      IRQ                                               95
      IRQ                                               96
      IRQ                                               97
      IRQ                                               98
      IRQ                                               99

  [   / Microsoft System Management BIOS  ]

     :
                                        Microsoft System Management BIOS 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\mssmbios

  [   / NVIDIA nForce PCI System Management ]

     :
                                        NVIDIA nForce PCI System Management
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_03EB&SUBSYS_82341043&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,1,1)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - SMBus Controller

     :
      IRQ                                               10
                                                    0600-063F
                                                    0700-073F
                                                    CC00-CC3F

  [   / Remote Desktop Device Redirector Bus ]

     :
                                        Remote Desktop Device Redirector Bus
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          rdpbus.inf
       ID                                     ROOT\RDPBUS

  [   / UMBus    ]

     :
                                        UMBus   
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     root\umbus

  [   / UMBus  ]

     :
                                        UMBus 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     UMB\UMBUS

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C04
      PnP-                                    Numeric Data Processor

     :
      IRQ                                               13
                                                    00F0-00FF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0800
      PnP-                                    PC Speaker

     :
                                                    0061-0061

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0103
      PnP-                                    High Precision Event Timer

     :
                                                  FED00000-FED00FFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\VOLMGR

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\RDP_KBD

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\RDP_MOU

  [   /     () ]

     :
                                            ()
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\vdrvroot

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          blbdrive.inf
       ID                                     ROOT\BLBDRIVE

  [   /   ACPI ]

     :
                                          ACPI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C0C
      PnP-                                    Power Button

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            19.11.2010
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          hdaudbus.inf
       ID                                     PCI\VEN_1002&DEV_AA60&SUBSYS_AA601043&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(2,0,1)
      PCI-                                    ATI Redwood/Madison - High Definition Audio Controller

     :
      IRQ                                               18
                                                  DFFBC000-DFFBFFFF

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0200
      PnP-                                    DMA Controller

     :
      DMA                                               04
                                                    0000-000F
                                                    0081-0083
                                                    0087-0087
                                                    0089-008B
                                                    008F-008F
                                                    00C0-00DF

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     LPTENUM\MicrosoftRawPort958A
                                     LPT1

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          compositebus.inf
       ID                                     ROOT\CompositeBus

  [   /    Plug and Play ]

     :
                                           Plug and Play
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     root\swenum

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0000
      PnP-                                    Programmable Interrupt Controller

     :
                                                    0020-0021
                                                    00A0-00A1

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  E0000000-EFFFFFFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  FEC00000-FEC00FFF
                                                  FEE00000-FEE00FFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  000D0000-000D3FFF
                                                  000D4000-000D7FFF
                                                  000DE000-000DFFFF
                                                  FEE01000-FEEFFFFF
                                                  FEFE0000-FEFE01FF
                                                  FEFE1000-FEFE1FFF
                                                  FF300000-FF3FFFFF
                                                  FFB80000-FFFFFFFF
                                                    0010-001F
                                                    0022-003F
                                                    0044-004D
                                                    0050-005F
                                                    0062-0063
                                                    0065-006F
                                                    0072-007F
                                                    0080-0080
                                                    0084-0086
                                                    0088-0088
                                                    008C-008E
                                                    0090-009F
                                                    00A2-00BF
                                                    00E0-00EF
                                                    04D0-04D1
                                                    0500-057F
                                                    0580-05FF
                                                    0800-080F
                                                    0800-087F
                                                    0880-08FF
                                                    0900-097F
                                                    0980-09FF
                                                    0D00-0D7F
                                                    0D80-0DFF
                                                    2000-207F
                                                    2080-20FF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                    0230-023F
                                                    0290-029F
                                                    0A00-0A0F
                                                    0A10-0A1F

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C01
      PnP-                                    System Board Extension

     :
                                                  00000000-0009FFFF
                                                  000C0000-000CFFFF
                                                  000E0000-000FFFFF
                                                  00100000-BFFFFFFF
                                                  FF780000-FFFFFFFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0100
      PnP-                                    System Timer

     :
      IRQ                                               00
                                                    0040-0043

  [   /  PCI- RAM ]

     :
                                         PCI- RAM
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_03EA&SUBSYS_82341043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,0,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - Host Bridge (HyperTransport)

  [   /  PCI- RAM ]

     :
                                         PCI- RAM
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_03F5&SUBSYS_82341043&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,1,2)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - Shape/Trim

  [   /   PCI - ISA ]

     :
                                          PCI - ISA
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_03E0&SUBSYS_82341043&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,1,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - LPC Bridge

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_03E8&SUBSYS_000010DE&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,9,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x16)

     :
      IRQ                                               131072
                                                  000A0000-000BFFFF
                                                  C0000000-CFFFFFFF
                                                  DFF00000-DFFFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    E000-EFFF

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_03E9&SUBSYS_000010DE&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,11,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1)

     :
      IRQ                                               131072

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_03E9&SUBSYS_000010DE&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,12,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1)

     :
      IRQ                                               131072

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_03F3&SUBSYS_CB8410DE&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,4,0)
      PCI-                                    nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI-PCI Bridge

     :
                                                    D000-DFFF

  [   /    ACPI ]

     :
                                           ACPI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\FixedButton

  [   /  PCI ]

     :
                                         PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0A03
      PnP-                                    PCI Bus

     :
                                                  000A0000-000BFFFF
                                                  000D0000-000DFFFF
                                                  C0000000-FF77FFFF
                                                    0000-0CF7
                                                    0D00-FFFF

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    / FaceCam 300 ]

     :
                                        FaceCam 300
                                            22.04.2009
                                          1.0.0.28
                                       KYE
      INF-                                          oem2.inf
       ID                                     USB\VID_093A&PID_2627&REV_0100
                                     Port_#0001.Hub_#0001


--------[   ]---------------------------------------------------------------------------------------

     PCI:
       0,  24,  1                  AMD Hammer - Address Map
       0,  24,  2                  AMD Hammer - DRAM Controller
       0,  24,  0                  AMD Hammer - HyperTransport Technology Configuration
       0,  24,  3                  AMD Hammer - Miscellaneous Control
       2,  0,  0                   ATI Radeon HD 5570 (Redwood) Video Adapter
       2,  0,  1                   ATI Redwood/Madison - High Definition Audio Controller
       1,  8,  0                   C-Media CMI8738/C3DX Audio Device
       0,  2,  1                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - EHCI USB 2.0 Controller
       0,  0,  0                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - Host Bridge (HyperTransport)
       0,  7,  0                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - LAN Controller
       0,  1,  0                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - LPC Bridge
       0,  2,  0                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - OHCI USB 1.1 Controller
       0,  6,  0                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - Parallel ATA Controller
       0,  11,  0                  nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1)
       0,  12,  0                  nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1)
       0,  9,  0                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x16)
       0,  4,  0                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI-PCI Bridge
       0,  8,  0                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller
       0,  8,  1                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller
       0,  1,  2                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - Shape/Trim
       0,  1,  1                   nVIDIA nForce 6100-400/405/420/430 (MCP61) - SMBus Controller

     PnP:
      PNP0303                                           101/102-Key or MS Natural Keyboard
      PNP0501                                           16550A-compatible UART Serial Port
      PNP0C08                                           ACPI Driver/BIOS
      AUTHENTICAMD_-_AMD64_FAMILY_15_MODEL_107_-_AMD_ATHLON(TM)_64_X2_DUAL_CORE_PROCESSOR_5000+AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
      AUTHENTICAMD_-_AMD64_FAMILY_15_MODEL_107_-_AMD_ATHLON(TM)_64_X2_DUAL_CORE_PROCESSOR_5000+AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
      ATK0110                                           Asus ATK-110 ACPI Utility
      PNP0200                                           DMA Controller
      PNP0700                                           Floppy Disk Controller
      PNP0103                                           High Precision Event Timer
      PNP0F03                                           Microsoft PS/2 Port Mouse
      PNP0C04                                           Numeric Data Processor
      PNP0400                                           Parallel Port
      PNP0800                                           PC Speaker
      PNP0A03                                           PCI Bus
      PNP0C0C                                           Power Button
      PNP0000                                           Programmable Interrupt Controller
      PNP0B00                                           Real-Time Clock
      PNP0C01                                           System Board Extension
      PNP0100                                           System Timer
      TEREDO                                            Teredo Tunneling Pseudo-Interface
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      ISATAP                                             Microsoft ISATAP
      FIXEDBUTTON                                          ACPI

     LPT PnP:
      MICROSOFTRAWPORT                                     

     USB:
      093A 2627                                         FaceCam 300
      125F A13A                                            USB

    :
      COM1                                                (COM1)
      LPT1                                                (LPT1)


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ AMD Hammer - Address Map ]

     :
                                      AMD Hammer - Address Map
                                                 PCI
       /  /                        0 / 24 / 1
      ID                                      1022-1101
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD Hammer - DRAM Controller ]

     :
                                      AMD Hammer - DRAM Controller
                                                 PCI
       /  /                        0 / 24 / 2
      ID                                      1022-1102
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD Hammer - HyperTransport Technology Configuration ]

     :
                                      AMD Hammer - HyperTransport Technology Configuration
                                                 PCI
       /  /                        0 / 24 / 0
      ID                                      1022-1100
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

    HyperTransport LDT0:
       HyperTransport                             1.02
                                                 
                                             
      .  /                    16  / 16 
        /          16  / 16 
                                1000 
                                     1000 
       /                     0 / 0
      Isochronous Flow Control Mode                      
      CRC Error Detected                                
      CRC Test Mode                                      
      Extended CTL Required                             
      Extended Register Set                              
      HyperTransport Stop Mode                          
      Link Failure Detected                             

  [ AMD Hammer - Miscellaneous Control ]

     :
                                      AMD Hammer - Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 3
      ID                                      1022-1103
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ ATI Radeon HD 5570 (Redwood) Video Adapter ]

     :
                                      ATI Radeon HD 5570 (Redwood) Video Adapter
                                                 PCI Express 2.0 x16
       /  /                        2 / 0 / 0
      ID                                      1002-68D9
                               1043-036C
                                         0300 (VGA Display Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/Pages/graphics.aspx
                                       http://sites.amd.com/us/game/downloads/Pages/downloads.aspx
                                     http://www.aida64.com/driver-updates

  [ ATI Redwood/Madison - High Definition Audio Controller ]

     :
                                      ATI Redwood/Madison - High Definition Audio Controller
                                                 PCI Express 2.0 x16
       /  /                        2 / 0 / 1
      ID                                      1002-AA60
                               1043-AA60
                                         0403 (High Definition Audio)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ C-Media CMI8738/C3DX Audio Device ]

     :
                                      C-Media CMI8738/C3DX Audio Device
                                                 PCI
       /  /                        1 / 8 / 0
      ID                                      13F6-0111
                               13F6-0111
                                         0401 (Audio Device)
                                                  10
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - EHCI USB 2.0 Controller ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - EHCI USB 2.0 Controller
                                                 PCI
       /  /                        0 / 2 / 1
      ID                                      10DE-03F2
                               1043-8234
                                         0C03 (USB Controller)
                                                  A3
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - Host Bridge (HyperTransport) ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - Host Bridge (HyperTransport)
                                                 PCI
       /  /                        0 / 0 / 0
      ID                                      10DE-03EA
                               1043-8234
                                         0500 (RAM Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - LAN Controller ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - LAN Controller
                                                 PCI
       /  /                        0 / 7 / 0
      ID                                      10DE-03EF
                               1043-8234
                                         0680 (Bridge Device)
                                                  A2
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - LPC Bridge ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - LPC Bridge
                                                 PCI
       /  /                        0 / 1 / 0
      ID                                      10DE-03E0
                               1043-8234
                                         0601 (PCI/ISA Bridge)
                                                  A2
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - OHCI USB 1.1 Controller ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - OHCI USB 1.1 Controller
                                                 PCI
       /  /                        0 / 2 / 0
      ID                                      10DE-03F1
                               1043-8234
                                         0C03 (USB Controller)
                                                  A3
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - Parallel ATA Controller ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - Parallel ATA Controller
                                                 PCI
       /  /                        0 / 6 / 0
      ID                                      10DE-03EC
                               1043-8234
                                         0101 (IDE Controller)
                                                  A2
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1) ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1)
                                                 PCI
       /  /                        0 / 11 / 0
      ID                                      10DE-03E9
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A2
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1) ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1)
                                                 PCI
       /  /                        0 / 12 / 0
      ID                                      10DE-03E9
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A2
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x16) ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x16)
                                                 PCI
       /  /                        0 / 9 / 0
      ID                                      10DE-03E8
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A2
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI-PCI Bridge ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI-PCI Bridge
                                                 PCI
       /  /                        0 / 4 / 0
      ID                                      10DE-03F3
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller
                                                 PCI
       /  /                        0 / 8 / 0
      ID                                      10DE-03F6
                               1043-8234
                                         0101 (IDE Controller)
                                                  A2
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller
                                                 PCI
       /  /                        0 / 8 / 1
      ID                                      10DE-03F6
                               1043-8234
                                         0101 (IDE Controller)
                                                  A2
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - Shape/Trim ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - Shape/Trim
                                                 PCI
       /  /                        0 / 1 / 2
      ID                                      10DE-03F5
                               1043-8234
                                         0500 (RAM Controller)
                                                  A2
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 6100-400/405/420/430 (MCP61) - SMBus Controller ]

     :
                                      nVIDIA nForce 6100-400/405/420/430 (MCP61) - SMBus Controller
                                                 PCI
       /  /                        0 / 1 / 1
      ID                                      10DE-03EB
                               1043-8234
                                         0C05 (SMBus Controller)
                                                  A2
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     


--------[  USB ]----------------------------------------------------------------------------------------------

  [ FaceCam 300 ]

     :
                                      FaceCam 300
      ID                                      093A-2627
                                         FF / FF
                                      FF
        USB                         1.10
                                         Full  (USB 1.1)

  [    USB (NH13) ]

     :
                                         USB
      ID                                      125F-A13A
                                         08 / 06 (Mass Storage)
                                      50
                                           ADATA
                                                 NH13
                                           A13A0052011080200118
        USB                         2.10
                                         High  (USB 2.0)


--------[   ]-------------------------------------------------------------------------------------------

    DMA 02                                  
    DMA 04                                   
    IRQ 00                                
    IRQ 01                                 PS/2
    IRQ 04                                 (COM1)
    IRQ 06                                  
    IRQ 08                               CMOS  
    IRQ 10                                        NVIDIA nForce PCI System Management
    IRQ 100                              Microsoft ACPI- 
    IRQ 101                              Microsoft ACPI- 
    IRQ 102                              Microsoft ACPI- 
    IRQ 103                              Microsoft ACPI- 
    IRQ 104                              Microsoft ACPI- 
    IRQ 105                              Microsoft ACPI- 
    IRQ 106                              Microsoft ACPI- 
    IRQ 107                              Microsoft ACPI- 
    IRQ 108                              Microsoft ACPI- 
    IRQ 109                              Microsoft ACPI- 
    IRQ 110                              Microsoft ACPI- 
    IRQ 111                              Microsoft ACPI- 
    IRQ 112                              Microsoft ACPI- 
    IRQ 113                              Microsoft ACPI- 
    IRQ 114                              Microsoft ACPI- 
    IRQ 115                              Microsoft ACPI- 
    IRQ 116                              Microsoft ACPI- 
    IRQ 117                              Microsoft ACPI- 
    IRQ 118                              Microsoft ACPI- 
    IRQ 119                              Microsoft ACPI- 
    IRQ 12                               Microsoft PS/2 
    IRQ 120                              Microsoft ACPI- 
    IRQ 121                              Microsoft ACPI- 
    IRQ 122                              Microsoft ACPI- 
    IRQ 123                              Microsoft ACPI- 
    IRQ 124                              Microsoft ACPI- 
    IRQ 125                              Microsoft ACPI- 
    IRQ 126                              Microsoft ACPI- 
    IRQ 127                              Microsoft ACPI- 
    IRQ 128                              Microsoft ACPI- 
    IRQ 129                              Microsoft ACPI- 
    IRQ 13                                
    IRQ 130                              Microsoft ACPI- 
    IRQ 131                              Microsoft ACPI- 
    IRQ 131072                             PCI - PCI
    IRQ 131072                             PCI - PCI
    IRQ 131072                             PCI - PCI
    IRQ 132                              Microsoft ACPI- 
    IRQ 133                              Microsoft ACPI- 
    IRQ 134                              Microsoft ACPI- 
    IRQ 135                              Microsoft ACPI- 
    IRQ 136                              Microsoft ACPI- 
    IRQ 137                              Microsoft ACPI- 
    IRQ 138                              Microsoft ACPI- 
    IRQ 139                              Microsoft ACPI- 
    IRQ 14                               ATA Channel 0
    IRQ 140                              Microsoft ACPI- 
    IRQ 141                              Microsoft ACPI- 
    IRQ 142                              Microsoft ACPI- 
    IRQ 143                              Microsoft ACPI- 
    IRQ 144                              Microsoft ACPI- 
    IRQ 145                              Microsoft ACPI- 
    IRQ 146                              Microsoft ACPI- 
    IRQ 147                              Microsoft ACPI- 
    IRQ 148                              Microsoft ACPI- 
    IRQ 149                              Microsoft ACPI- 
    IRQ 15                               ATA Channel 1
    IRQ 150                              Microsoft ACPI- 
    IRQ 151                              Microsoft ACPI- 
    IRQ 152                              Microsoft ACPI- 
    IRQ 153                              Microsoft ACPI- 
    IRQ 154                              Microsoft ACPI- 
    IRQ 155                              Microsoft ACPI- 
    IRQ 156                              Microsoft ACPI- 
    IRQ 157                              Microsoft ACPI- 
    IRQ 158                              Microsoft ACPI- 
    IRQ 159                              Microsoft ACPI- 
    IRQ 160                              Microsoft ACPI- 
    IRQ 161                              Microsoft ACPI- 
    IRQ 162                              Microsoft ACPI- 
    IRQ 163                              Microsoft ACPI- 
    IRQ 164                              Microsoft ACPI- 
    IRQ 165                              Microsoft ACPI- 
    IRQ 166                              Microsoft ACPI- 
    IRQ 167                              Microsoft ACPI- 
    IRQ 168                              Microsoft ACPI- 
    IRQ 169                              Microsoft ACPI- 
    IRQ 17                                        C-Media PCI Audio Device
    IRQ 170                              Microsoft ACPI- 
    IRQ 171                              Microsoft ACPI- 
    IRQ 172                              Microsoft ACPI- 
    IRQ 173                              Microsoft ACPI- 
    IRQ 174                              Microsoft ACPI- 
    IRQ 175                              Microsoft ACPI- 
    IRQ 176                              Microsoft ACPI- 
    IRQ 177                              Microsoft ACPI- 
    IRQ 178                              Microsoft ACPI- 
    IRQ 179                              Microsoft ACPI- 
    IRQ 18                                         High Definition Audio (Microsoft)
    IRQ 180                              Microsoft ACPI- 
    IRQ 181                              Microsoft ACPI- 
    IRQ 182                              Microsoft ACPI- 
    IRQ 183                              Microsoft ACPI- 
    IRQ 184                              Microsoft ACPI- 
    IRQ 185                              Microsoft ACPI- 
    IRQ 186                              Microsoft ACPI- 
    IRQ 187                              Microsoft ACPI- 
    IRQ 188                              Microsoft ACPI- 
    IRQ 189                              Microsoft ACPI- 
    IRQ 190                              Microsoft ACPI- 
    IRQ 20                                          NVIDIA nForce
    IRQ 20                                         NVIDIA nForce Serial ATA
    IRQ 21                                         NVIDIA nForce Serial ATA
    IRQ 22                                          PCI - USB -
    IRQ 23                                         OpenHCD USB -
    IRQ 65536                            ATI Radeon HD 5500 Series
    IRQ 81                               Microsoft ACPI- 
    IRQ 82                               Microsoft ACPI- 
    IRQ 83                               Microsoft ACPI- 
    IRQ 84                               Microsoft ACPI- 
    IRQ 85                               Microsoft ACPI- 
    IRQ 86                               Microsoft ACPI- 
    IRQ 87                               Microsoft ACPI- 
    IRQ 88                               Microsoft ACPI- 
    IRQ 89                               Microsoft ACPI- 
    IRQ 90                               Microsoft ACPI- 
    IRQ 91                               Microsoft ACPI- 
    IRQ 92                               Microsoft ACPI- 
    IRQ 93                               Microsoft ACPI- 
    IRQ 94                               Microsoft ACPI- 
    IRQ 95                               Microsoft ACPI- 
    IRQ 96                               Microsoft ACPI- 
    IRQ 97                               Microsoft ACPI- 
    IRQ 98                               Microsoft ACPI- 
    IRQ 99                               Microsoft ACPI- 
     00000000-0009FFFF              
     000A0000-000BFFFF                      ATI Radeon HD 5500 Series
     000A0000-000BFFFF                       PCI
     000A0000-000BFFFF                 PCI - PCI
     000C0000-000CFFFF              
     000D0000-000D3FFF                        
     000D0000-000DFFFF                       PCI
     000D4000-000D7FFF                        
     000DE000-000DFFFF                        
     000E0000-000FFFFF              
     00100000-BFFFFFFF              
     C0000000-CFFFFFFF             ATI Radeon HD 5500 Series
     C0000000-CFFFFFFF               PCI - PCI
     C0000000-FF77FFFF                       PCI
     DFEF7000-DFEF7FFF              NVIDIA nForce Serial ATA
     DFEFC000-DFEFCFFF              NVIDIA nForce Serial ATA
     DFEFD000-DFEFDFFF               NVIDIA nForce
     DFEFEC00-DFEFECFF               PCI - USB -
     DFEFF000-DFEFFFFF              OpenHCD USB -
     DFF00000-DFFFFFFF               PCI - PCI
     DFFBC000-DFFBFFFF              High Definition Audio (Microsoft)
     DFFE0000-DFFFFFFF             ATI Radeon HD 5500 Series
     E0000000-EFFFFFFF               
     FEC00000-FEC00FFF               
     FED00000-FED00FFF               
     FEE00000-FEE00FFF               
     FEE01000-FEEFFFFF               
     FEFE0000-FEFE01FF               
     FEFE1000-FEFE1FFF               
     FF300000-FF3FFFFF               
     FF780000-FFFFFFFF              
     FFB80000-FFFFFFFF               
     0000-000F                           
     0000-0CF7                                 PCI
     0010-001F                         
     0020-0021                         
     0022-003F                         
     0040-0043                        
     0044-004D                         
     0050-005F                         
     0060-0060                         PS/2
     0061-0061                        
     0062-0063                         
     0064-0064                         PS/2
     0065-006F                         
     0070-0071                       CMOS  
     0072-007F                         
     0080-0080                         
     0081-0083                           
     0084-0086                         
     0087-0087                           
     0088-0088                         
     0089-008B                           
     008C-008E                         
     008F-008F                           
     0090-009F                         
     00A0-00A1                         
     00A2-00BF                         
     00C0-00DF                           
     00E0-00EF                         
     00F0-00FF                        
     0170-0177                       ATA Channel 1
     01F0-01F7                       ATA Channel 0
     0230-023F                         
     0290-029F                         
     0376-0376                       ATA Channel 1
     0378-037F                         (LPT1)
     03B0-03BB                                ATI Radeon HD 5500 Series
     03B0-03BB                           PCI - PCI
     03C0-03DF                                ATI Radeon HD 5500 Series
     03C0-03DF                           PCI - PCI
     03F0-03F5                          
     03F6-03F6                       ATA Channel 0
     03F7-03F7                          
     03F8-03FF                         (COM1)
     04D0-04D1                         
     0500-057F                         
     0580-05FF                         
     0600-063F                       NVIDIA nForce PCI System Management
     0700-073F                       NVIDIA nForce PCI System Management
     0800-080F                         
     0800-087F                         
     0880-08FF                         
     0900-097F                         
     0980-09FF                         
     0A00-0A0F                         
     0A10-0A1F                         
     0D00-0D7F                         
     0D00-FFFF                                 PCI
     0D80-0DFF                         
     2000-207F                         
     2080-20FF                         
     B000-B00F                        NVIDIA nForce Serial ATA
     B080-B083                        NVIDIA nForce Serial ATA
     B400-B407                        NVIDIA nForce Serial ATA
     B480-B483                        NVIDIA nForce Serial ATA
     B800-B807                        NVIDIA nForce Serial ATA
     B880-B88F                        NVIDIA nForce Serial ATA
     BC00-BC03                        NVIDIA nForce Serial ATA
     C000-C007                        NVIDIA nForce Serial ATA
     C080-C083                        NVIDIA nForce Serial ATA
     C400-C407                        NVIDIA nForce Serial ATA
     CC00-CC3F                       NVIDIA nForce PCI System Management
     D000-DFFF                         PCI - PCI
     D800-D8FF                       C-Media PCI Audio Device
     E000-EFFF                         PCI - PCI
     E800-E8FF                       ATI Radeon HD 5500 Series
     FFA0-FFAF                          PCI IDE


--------[  ]--------------------------------------------------------------------------------------------------------

  [   PS/2 ]

     :
                                        PS/2
                                           Japanese keyboard
                                     Russian
        ANSI                             1251 - @%SystemRoot%\system32\mlang.dll,-4611
        OEM                              866 - @%SystemRoot%\system32\mlang.dll,-4645
                                         1
                                         31

  [ Microsoft PS/2  ]

     :
                                            Microsoft PS/2 
                                         5
                                              
                                         1
                                     500 msec
       X / Y                                       6 / 10
                                 3

     :
                               
      ''                                
                
                                            
                   
                                              
      Sonar                                             

     :
                                                   Microsoft Corporation
                                     http://www.microsoft.com/products
                                       http://www.microsoft.com/downloads
                                     http://www.aida64.com/driver-updates


--------[  ]----------------------------------------------------------------------------------------------------

  [ Fax ]

     :
                                             Fax
                                      
                                  
                                            SHRFAX:
                                         Microsoft Shared Fax Driver (v4.00)
                                           Fax
                                         winprint
                                     
                                             5:00 - 5:00
                                               1
                                 0
                                                  

     :
                                            Letter, 8.5 x 11 in
                                              
                                          200 x 200 dpi Mono

  [ Microsoft XPS Document Writer ( ) ]

     :
                                             Microsoft XPS Document Writer
                                      
                                  
                                            XPSPort:
                                         Microsoft XPS Document Writer (v6.00)
                                           Microsoft XPS Document Writer
                                         winprint
                                     
                                             
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color


--------[  ]------------------------------------------------------------------------------------------------

    APSDaemon                          Registry\Common\Run      C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe 
    avast                              Registry\Common\Run      C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui
    PAC7302_Monitor                    Registry\Common\Run      C:\Windows\PixArt\PAC7302\Monitor.exe 


--------[  ]---------------------------------------------------------------------------------------------

  [ GoogleUpdateTaskMachineCore ]

     :
                                               GoogleUpdateTaskMachineCore
                                                  
                                           C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                                     /c
                                            
                                               ,    Google  .      ,   Google   .      ,     ,     .    ,    Google,   .
                                        
                                               
                                         22.02.2012 14:32:25
                                         23.02.2012 14:02:00

     :
       #1                                            
       #2                                         14:02, ,   20.02.2012


--------[   ]-------------------------------------------------------------------------------------

    Adobe Flash Player 11 Plugin 64-bit                                                    11.1.102.62  
    AIDA64                                                                                         1.0  
    AMD Drag and Drop Transcoding                                                            2.00.0000  
    Apple Application Support [ ()]                                                 2.1.6  
    Apple Software Update [ ()]                                                 2.1.3.127  
    ATI AVIVO64 Codecs                                                                    11.6.0.50706  
    ATI Catalyst Install Manager                                                             3.0.782.0  
    avast! Free Antivirus                                                                   6.0.1367.0  
    Catalyst Control Center - Branding                                                       1.00.0000  
    Catalyst Control Center Graphics Previews Common                                  2010.0706.2128.36662  
    Catalyst Control Center Graphics Previews Vista                                   2010.0706.2128.36662  
    Catalyst Control Center InstallProxy                                              2010.0706.2128.36662  
    Catalyst Control Center Localization All                                          2010.0706.2128.36662  
    CCC Help Chinese Standard                                                         2010.0706.2127.36662  
    CCC Help Chinese Traditional                                                      2010.0706.2127.36662  
    CCC Help Czech                                                                    2010.0706.2127.36662  
    CCC Help Danish                                                                   2010.0706.2127.36662  
    CCC Help Dutch                                                                    2010.0706.2127.36662  
    CCC Help English                                                                  2010.0706.2127.36662  
    CCC Help Finnish                                                                  2010.0706.2127.36662  
    CCC Help French                                                                   2010.0706.2127.36662  
    CCC Help German                                                                   2010.0706.2127.36662  
    CCC Help Greek                                                                    2010.0706.2127.36662  
    CCC Help Hungarian                                                                2010.0706.2127.36662  
    CCC Help Italian                                                                  2010.0706.2127.36662  
    CCC Help Japanese                                                                 2010.0706.2127.36662  
    CCC Help Korean                                                                   2010.0706.2127.36662  
    CCC Help Norwegian                                                                2010.0706.2127.36662  
    CCC Help Polish                                                                   2010.0706.2127.36662  
    CCC Help Portuguese                                                               2010.0706.2127.36662  
    CCC Help Russian                                                                  2010.0706.2127.36662  
    CCC Help Spanish                                                                  2010.0706.2127.36662  
    CCC Help Swedish                                                                  2010.0706.2127.36662  
    CCC Help Thai                                                                     2010.0706.2127.36662  
    CCC Help Turkish                                                                  2010.0706.2127.36662  
    ccc-core-static                                                                   2010.0706.2128.36662  
    ccc-utility64                                                                     2010.0706.2128.36662  
    FaceCam 300 []                                                                     1.0.0.28  
    Google Update Helper                                                                     1.3.21.99  
    HydraVision                                                                              4.2.174.0  
    Microsoft .NET Framework 4 Client Profile RUS Language Pack [ ()]           4.0.30319  
    Microsoft .NET Framework 4 Client Profile                                                4.0.30319  
    Microsoft .NET Framework 4 Client Profile                                                4.0.30319  
    Microsoft .NET Framework 4 Extended RUS Language Pack [ ()]                 4.0.30319  
    Microsoft .NET Framework 4 Extended                                                      4.0.30319  
    Microsoft .NET Framework 4 Extended                                                      4.0.30319  
    Microsoft Office Access MUI (Russian) 2010 [ ()]                       14.0.4763.1000  
    Microsoft Office Excel MUI (Russian) 2010 [ ()]                        14.0.4763.1000  
    Microsoft Office Groove MUI (Russian) 2010 [ ()]                       14.0.4763.1000  
    Microsoft Office InfoPath MUI (Russian) 2010 [ ()]                     14.0.4763.1000  
    Microsoft Office Office 64-bit Components 2010                                      14.0.4763.1000  
    Microsoft Office OneNote MUI (Russian) 2010 [ ()]                      14.0.4763.1000  
    Microsoft Office Outlook MUI (Russian) 2010 [ ()]                      14.0.4763.1000  
    Microsoft Office PowerPoint MUI (Russian) 2010 [ ()]                   14.0.4763.1000  
    Microsoft Office Professional Plus 2010                                             14.0.4763.1000  
    Microsoft Office Proof (English) 2010                                               14.0.4763.1000  
    Microsoft Office Proof (German) 2010 [ ()]                          14.0.4763.1000  
    Microsoft Office Proof (Russian) 2010 [ ()]                            14.0.4763.1000  
    Microsoft Office Proof (Ukrainian) 2010 [ ()]                      14.0.4763.1000  
    Microsoft Office Proofing (Russian) 2010 [ ()]                         14.0.4763.1000  
    Microsoft Office Publisher MUI (Russian) 2010 [ ()]                    14.0.4763.1000  
    Microsoft Office Shared 64-bit MUI (Russian) 2010 [ ()]                14.0.4763.1000  
    Microsoft Office Shared MUI (Russian) 2010 [ ()]                       14.0.4763.1000  
    Microsoft Office Word MUI (Russian) 2010 [ ()]                         14.0.4763.1000  
    Microsoft Office   2010                                         14.0.4763.1000  
    Microsoft Visual C++ 2005 Redistributable                                                8.0.59193  
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148                      9.0.30729.4148  
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148                      9.0.30729.4148  
    Movavi   10 [ ()]                                             10.02.001  
    Safari [ ()]                                                                5.34.52.7  
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)                        1  
    Security Update for Microsoft .NET Framework 4 Extended (KB2416472)                              1  
    The KMPlayer (remove only)                                                                          
    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)                                 1  
    WinRAR 4.0.0 (64-)                                                                  4.0.0  
        Microsoft.NET Framework 4 - RUS                       4.0.30319  
        Microsoft.NET Framework 4 - RUS                        4.0.30319  


--------[  ]----------------------------------------------------------------------------------------------------

    Microsoft Internet Explorer 8.0.7601.17514                              D4F6K-QK3RD-TMVMJ-BBMRX-3MBMV
    Microsoft Office Professional Plus 2010                                 VYBBJ-TRJPB-QFQRF-QFT4D-H3GVB
    Microsoft Windows 7 Ultimate                                            D4F6K-QK3RD-TMVMJ-BBMRX-3MBMV


--------[   ]-------------------------------------------------------------------------------------------------

    386               Virtual Device Driver                                            
    3G2               3GPP2 Audio/Video                                                video/3gpp2
    3GP               3GPP Audio/Video                                                 video/3gpp
    3GP2              3GPP2 Audio/Video                                                video/3gpp2
    3GPP              3GPP Audio/Video                                                 video/3gpp
    AAC               ADTS Audio                                                       audio/vnd.dlna.adts
    ACCDA             Microsoft Access Add-in                                          application/msaccess.addin
    ACCDB             Microsoft Access                                       application/msaccess
    ACCDC             Microsoft Access Signed Package                                  application/msaccess.cab
    ACCDE             Microsoft Access ACCDE Database                                  application/msaccess.exec
    ACCDR             Microsoft Access Runtime Application                             application/msaccess.runtime
    ACCDT             Microsoft Access Template                                        application/msaccess.template
    ACCDU             Microsoft Access Add-in Data                                     
    ACCDW             Microsoft Access Web Application                                 application/msaccess.webapplication
    ACCFT             Microsoft Access Template                                        application/msaccess.ftemplate
    ACL               AutoCorrect List File                                            
    ADE               Microsoft Access Project Extension                               application/msaccess
    ADN               Microsoft Access Blank Project Template                          
    ADP               Microsoft Access Project                                         application/msaccess
    ADT               ADTS Audio                                                       audio/vnd.dlna.adts
    ADTS              ADTS Audio                                                       audio/vnd.dlna.adts
    AIF               AIFF Format Sound                                                audio/aiff
    AIFC              AIFF Format Sound                                                audio/aiff
    AIFF              AIFF Format Sound                                                audio/aiff
    ANI               Animated Cursor                                                  
    APPLICATION       Application Manifest                                             application/x-ms-application
    APPREF-MS         Application Reference                                            
    ASA               ASA File                                                         
    ASF               Windows Media Audio/Video file                                   video/x-ms-asf
    ASP               ASP File                                                         
    ASX               Windows Media Audio/Video playlist                               video/x-ms-asf
    AU                AU Format Sound                                                  audio/basic
    AVASTLIC          avast! license file                                              application/avast-license
    AVASTSOUNDS       avast! soundpack file                                            application/avast-sounds
    AVI               Video Clip                                                       video/avi
    AW                Answer Wizard File                                               
    BAT               Windows Batch File                                               
    BLG               Performance Monitor File                                         
    BMP               Bitmap Image                                                     image/bmp
    C2R               C2R File                                                         
    CAB               Cabinet File                                                     
    CAMP              WCS Viewing Condition Profile                                    
    CAT               Security Catalog                                                 application/vnd.ms-pki.seccat
    CDA               CD Audio Track                                                   
    CDC               Nero CoverDesigner Document                                      
    CDMP              WCS Device Profile                                               
    CDX               CDX File                                                         
    CER               Security Certificate                                             application/x-x509-ca-cert
    CHESSTITANSSAVE-MS  .ChessTitansSave-ms                                              
    CHK               Recovered File Fragments                                         
    CHM               Compiled HTML Help file                                          
    CMD               Windows Command Script                                           
    COM               MS-DOS Application                                               
    COMFYCAKESSAVE-MS  .ComfyCakesSave-ms                                               
    COMPOSITEFONT     Composite Font File                                              
    CONTACT           Contact File                                                     text/x-ms-contact
    CPL               Control Panel Item                                               
    CRD               Information Card                                                 
    CRDS              Information Card Store                                           
    CRL               Certificate Revocation List                                      application/pkix-crl
    CRT               Security Certificate                                             application/x-x509-ca-cert
    CRTX               Microsoft Office Chart                                    
    CSS               Cascading Style Sheet Document                                   text/css
    CSV                Microsoft Excel                                               
    CUE               Image Files                                                      
    CUR               Cursor                                                           
    DB                Data Base File                                                   
    DER               Security Certificate                                             application/x-x509-ca-cert
    DESKLINK          Desktop Shortcut                                                 
    DET                 Office                                               
    DIAGCAB           Diagnostic Cabinet                                               
    DIAGCFG           Diagnostic Configuration                                         
    DIAGPKG           Diagnostic Document                                              
    DIB               Bitmap Image                                                     image/bmp
    DIC               Text Document                                                    
    DLL               Application Extension                                            application/x-msdownload
    DOC                Microsoft Word 97-2003                                  application/msword
    DOCHTML            Microsoft Word   HTML                           
    DOCM               Microsoft Word                       application/vnd.ms-word.document.macroEnabled.12
    DOCMHTML          DOCMHTML File                                                    
    DOCX               Microsoft Word                                          application/vnd.openxmlformats-officedocument.wordprocessingml.document
    DOCXML             Microsoft Word   XML                            
    DOT                Microsoft Word 97-2003                                    application/msword
    DOTHTML            Microsoft Word   HTML                             
    DOTM               Microsoft Word                         application/vnd.ms-word.template.macroEnabled.12
    DOTX               Microsoft Word                                            application/vnd.openxmlformats-officedocument.wordprocessingml.template
    DOWNLOAD          DOWNLOAD File                                                    
    DQY                 ODBC  Microsoft Excel                            
    DRV               Device Driver                                                    
    DSN               Microsoft OLE DB Provider for ODBC Drivers                       
    DVR               Microsoft Recorded TV Show                                       
    DVR-MS            Microsoft Recorded TV Show                                       
    DWFX              XPS Document                                                     model/vnd.dwfx+xps
    EASMX             XPS Document                                                     model/vnd.easmx+xps
    EDRWX             XPS Document                                                     model/vnd.edrwx+xps
    ELM               Microsoft Office Themes File                                     
    EMF               EMF File                                                         
    EML                                                       
    EPRTX             XPS Document                                                     model/vnd.eprtx+xps
    EVT               EVT File                                                         
    EVTX              EVTX File                                                        
    EXC               Text Document                                                    
    EXE               Application                                                      application/x-msdownload
    FDM                 Outlook                                        
    FON               Font file                                                        
    FREECELLSAVE-MS   .FreeCellSave-ms                                                 
    GADGET            Windows Gadget                                                   
    GCSX                 Microsoft Office SmartArt                  
    GIF               GIF Image                                                        image/gif
    GLOX                Microsoft Office SmartArt                          
    GMMP              WCS Gamut Mapping Profile                                        
    GQSX              -  Microsoft Office SmartArt                 
    GROUP             Contact Group File                                               text/x-ms-group
    GRP               Microsoft Program Group                                          
    H1C               Windows Help Collection Definition File                          
    H1D               Windows Help Validator File                                      
    H1F               Windows Help Include File                                        
    H1H               Windows Help Merged Hierarchy                                    
    H1K               Windows Help Index File                                          
    H1Q               Windows Help Merged Query Index                                  
    H1S               Compiled Windows Help file                                       
    H1T               Windows Help Table of Contents File                              
    H1V               Windows Help Virtual Topic Definition File                       
    H1W               Windows Help Merged Keyword Index                                
    HEARTSSAVE-MS     .HeartsSave-ms                                                   
    HLP               Help File                                                        
    HOL                Outlook                                                
    HTA               HTML Application                                                 application/hta
    HTM               HTML Document                                                    text/html
    HTML              HTML Document                                                    text/html
    HXA               Microsoft Help Attribute Definition File                         application/xml
    HXC               Microsoft Help Collection Definition File                        application/xml
    HXD               Microsoft Help Validator File                                    application/octet-stream
    HXE               Microsoft Help Samples Definition File                           application/xml
    HXF               Microsoft Help Include File                                      application/xml
    HXH               Microsoft Help Merged Hierarchy File                             application/octet-stream
    HXI               Microsoft Help Compiled Index File                               application/octet-stream
    HXK               Microsoft Help Index File                                        application/xml
    HXQ               Microsoft Help Merged Query Index File                           application/octet-stream
    HXR               Microsoft Help Merged Attribute Index File                       application/octet-stream
    HXS               Microsoft Help Compiled Storage File                             application/octet-stream
    HXT               Microsoft Help Table of Contents File                            application/xml
    HXV               Microsoft Help Virtual Topic Definition File                     application/xml
    HXW               Microsoft Help Attribute Definition File                         application/octet-stream
    ICC               ICC Profile                                                      
    ICL               Icon Library                                                     
    ICM               ICC Profile                                                      
    ICO               Icon                                                             image/x-icon
    ICS                iCalendar                                                   text/calendar
    IMG               Image Files                                                      
    INF               Setup Information                                                
    INI               Configuration Settings                                           
    IQY                -  Microsoft Excel                             text/x-ms-iqy
    ISO               Image Files                                                      
    JFIF              JPEG Image                                                       image/jpeg
    JNT               Journal Document                                                 
    JOB               Task Scheduler Task Object                                       
    JOD               Microsoft.Jet.OLEDB.4.0                                          
    JPE               JPEG Image                                                       image/jpeg
    JPEG              JPEG Image                                                       image/jpeg
    JPG               JPEG Image                                                       image/jpeg
    JS                JScript Script File                                              
    JSE               JScript Encoded File                                             
    JTP               Journal Template                                                 
    JTX               XPS Document                                                     application/x-jtx+xps
    LABEL             Property List                                                    
    LACCDB            Microsoft Access Record-Locking Information                      
    LDB               Microsoft Access Record-Locking Information                      
    LEX               Dictionary File                                                  
    LIBRARY-MS        Library Folder                                                   application/windows-library+xml
    LNK               Shortcut                                                         
    LOG               Text Document                                                    
    M1V               Movie Clip                                                       video/mpeg
    M2T               AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    M2TS              AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    M2V               Movie Clip                                                       video/mpeg
    M3U               M3U file                                                         audio/x-mpegurl
    M4A               MPEG-4 Audio                                                     audio/mp4
    M4V               MP4 Video                                                        video/mp4
    MAD               Microsoft Access Module Shortcut                                 
    MAF               Microsoft Access Form Shortcut                                   
    MAG               Microsoft Access Diagram Shortcut                                
    MAHJONGTITANSSAVE-MS  .MahjongTitansSave-ms                                            
    MAM               Microsoft Access Macro Shortcut                                  
    MAPIMAIL          Mail Service                                                     
    MAQ               Microsoft Access Query Shortcut                                  
    MAR               Microsoft Access Report Shortcut                                 
    MAS               Microsoft Access Stored Procedure Shortcut                       
    MAT               Microsoft Access Table Shortcut                                  
    MAU               MAU File                                                         
    MAV               Microsoft Access View Shortcut                                   
    MAW               Microsoft Access Data Access Page Shortcut                       
    MCL               MCL File                                                         
    MDA               Microsoft Access Add-in                                          application/msaccess
    MDB               Microsoft Access Database                                        application/msaccess
    MDBHTML           Microsoft Access HTML Document                                   
    MDE               Microsoft Access MDE Database                                    application/msaccess
    MDN               Microsoft Access Blank Database Template                         
    MDT               Microsoft Access Add-in Data                                     
    MDW               Microsoft Access Workgroup Information                           
    MGC               Media Catalog File                                               
    MHT               MHTML Document                                                   message/rfc822
    MHTML             MHTML Document                                                   message/rfc822
    MID               MIDI Sequence                                                    audio/mid
    MIDI              MIDI Sequence                                                    audio/mid
    MIG               Migration Store                                                  
    MINESWEEPERSAVE-MS  .MinesweeperSave-ms                                              
    MLC               Language Pack File_                                              
    MML               Media Catalog File                                               
    MMW               Media Catalog File                                               
    MOD               Movie Clip                                                       video/mpeg
    MOV               QuickTime Movie                                                  video/quicktime
    MP2               MP3 Format Sound                                                 audio/mpeg
    MP2V              Movie Clip                                                       video/mpeg
    MP3               MP3 Format Sound                                                 audio/mpeg
    MP4               MP4 Video                                                        video/mp4
    MP4V              MP4 Video                                                        video/mp4
    MPA               Movie Clip                                                       video/mpeg
    MPE               Movie Clip                                                       video/mpeg
    MPEG              Movie Clip                                                       video/mpeg
    MPF               Clip Organizer Media Package File                                application/vnd.ms-mediapackage
    MPG               Movie Clip                                                       video/mpeg
    MPV2              Movie Clip                                                       video/mpeg
    MSC               Microsoft Common Console Document                                
    MSDVD             MSDVD File                                                       
    MSG                Outlook                                                  
    MSI               Windows Installer Package                                        
    MSP               Windows Installer Patch                                          
    MSRCINCIDENT      Windows Remote Assistance Invitation                             
    MSSTYLES          Windows Visual Style File                                        
    MSU               Microsoft Update Standalone Package                              
    MTS               AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    MYDOCS            MyDocs Drop Target                                               
    NBS               CD-ROM (SecurDisc) Compilation                                   
    NBV               BDMV Compilation                                                 
    NCD               Nero CoverDesigner Document                                      
    NCP               Check Point Compilation                                          
    NCT               Nero CoverDesigner Template                                      
    NCW               Nero CoverDesigner Wizard File                                   
    NDS               DiscSpan Compilation                                             
    NFO               MSInfo Configuration File                                        
    NHB               AVCHD(TM) BD Compilation                                         
    NHD               AVCHD(TM) DVD Compilation                                        
    NK2                 Outlook                                         
    NRA               Audio CD Compilation                                             
    NRB               CD-ROM (Boot) Compilation                                        
    NRC               CD-ROM (UDF/ISO) Compilation                                     
    NRD               DVD-Video Compilation                                            
    NRE               CD EXTRA Compilation                                             
    NRG               Disc Image                                                       
    NRI               CD-ROM (ISO) Compilation                                         
    NRJ               NRJ File                                                         
    NRM               Mixed Mode CD Compilation                                        
    NRU               CD-ROM (UDF) Compilation                                         
    OCX               ActiveX control                                                  
    ODC               Microsoft Office Data Connection                                 text/x-ms-odc
    ODCCUBEFILE       ODCCUBEFILE File                                                 
    ODCDATABASEFILE   ODCDATABASEFILE File                                             
    ODCNEWFILE        ODCNEWFILE File                                                  
    ODCTABLEFILE      ODCTABLEFILE File                                                
    ODP                OpenDocument                                         application/vnd.oasis.opendocument.presentation
    ODS                 OpenDocument                                 application/vnd.oasis.opendocument.spreadsheet
    ODT                OpenDocument                                               application/vnd.oasis.opendocument.text
    OFS                 Outlook                                             
    OFT                 Outlook                                          
    OPC               Microsoft Clean-up Wizard File                                   
    OQY                 OLAP  Microsoft Excel                            
    OSDX              OpenSearch Description File                                      application/opensearchdescription+xml
    OST                 Outlook                                              
    OTF               OpenType Font file                                               
    OTM                 Outlook VBA                                         
    P10               Certificate Request                                              application/pkcs10
    P12               Personal Information Exchange                                    application/x-pkcs12
    P7B               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    P7C               Digital ID File                                                  application/pkcs7-mime
    P7M               PKCS #7 MIME Message                                             application/pkcs7-mime
    P7R               Certificate Request Response                                     application/x-pkcs7-certreqresp
    P7S               PKCS #7 Signature                                                application/pkcs7-signature
    PAB                  Outlook                                    
    PBK               Dial-Up Phonebook                                                
    PCB               PCB File                                                         
    PERFMONCFG        Performance Monitor Configuration                                
    PFM               Type 1 Font file                                                 
    PFX               Personal Information Exchange                                    application/x-pkcs12
    PIF               Shortcut to MS-DOS Program                                       
    PKO               Public Key Security Object                                       application/vnd.ms-pki.pko
    PNF               Precompiled Setup Information                                    
    PNG               PNG Image                                                        image/png
    POT                Microsoft PowerPoint 97-2003                              application/vnd.ms-powerpoint
    POTHTML           HTML- Microsoft PowerPoint                                 
    POTM                Microsoft PowerPoint        application/vnd.ms-powerpoint.template.macroEnabled.12
    POTX               Microsoft PowerPoint                                      application/vnd.openxmlformats-officedocument.presentationml.template
    PPA                Microsoft PowerPoint 97-2003                          application/vnd.ms-powerpoint
    PPAM               Microsoft PowerPoint                                  application/vnd.ms-powerpoint.addin.macroEnabled.12
    PPS                 Microsoft PowerPoint 97-2003                       application/vnd.ms-powerpoint
    PPSM                Microsoft PowerPoint            application/vnd.ms-powerpoint.slideshow.macroEnabled.12
    PPSX                Microsoft PowerPoint                               application/vnd.openxmlformats-officedocument.presentationml.slideshow
    PPT                Microsoft PowerPoint 97-2003                         application/vnd.ms-powerpoint
    PPTHTML           HTML- Microsoft PowerPoint                               
    PPTM               Microsoft PowerPoint              application/vnd.ms-powerpoint.presentation.macroEnabled.12
    PPTMHTML          PPTMHTML File                                                    
    PPTX               Microsoft PowerPoint                                 application/vnd.openxmlformats-officedocument.presentationml.presentation
    PPTXML            XML- Microsoft PowerPoint                             
    PRF               PICS Rules File                                                  application/pics-rules
    PRINTEREXPORT     Printer Migration File                                           
    PS1               PS1 File                                                         
    PS1XML            PS1XML File                                                      
    PSC1              PSC1 File                                                        application/PowerShell
    PSD1              PSD1 File                                                        
    PSM1              PSM1 File                                                        
    PST                 Outlook                                              
    PURBLEPAIRSSAVE-MS  .PurblePairsSave-ms                                              
    PURBLESHOPSAVE-MS  .PurbleShopSave-ms                                               
    PWZ                Microsoft PowerPoint                                      application/vnd.ms-powerpoint
    QDS               Directory Query                                                  
    R00                WinRAR                                                     
    R01                WinRAR                                                     
    R02                WinRAR                                                     
    R03                WinRAR                                                     
    R04                WinRAR                                                     
    R05                WinRAR                                                     
    R06                WinRAR                                                     
    R07                WinRAR                                                     
    R08                WinRAR                                                     
    R09                WinRAR                                                     
    R10                WinRAR                                                     
    R11                WinRAR                                                     
    R12                WinRAR                                                     
    R13                WinRAR                                                     
    R14                WinRAR                                                     
    R15                WinRAR                                                     
    R16                WinRAR                                                     
    R17                WinRAR                                                     
    R18                WinRAR                                                     
    R19                WinRAR                                                     
    R20                WinRAR                                                     
    R21                WinRAR                                                     
    R22                WinRAR                                                     
    R23                WinRAR                                                     
    R24                WinRAR                                                     
    R25                WinRAR                                                     
    R26                WinRAR                                                     
    R27                WinRAR                                                     
    R28                WinRAR                                                     
    R29                WinRAR                                                     
    RAR                WinRAR                                                     
    RAT               Rating System File                                               application/rat-file
    RDP               Remote Desktop Connection                                        
    REG               Registration Entries                                             
    RELS              XML Document                                                     
    RESMONCFG         Resource Monitor Configuration                                   
    REV                RAR                                         
    RLE               RLE File                                                         
    RLL               Application Extension                                            
    RMI               MIDI Sequence                                                    audio/mid
    RQY                 OLE DB  Microsoft Excel                          text/x-ms-rqy
    RTF                RTF                                                       application/msword
    SAFARIEXTZ        SAFARIEXTZ File                                                  
    SCF               Windows Explorer Command                                         
    SCP               Text Document                                                    
    SCR               Screen saver                                                     
    SCT               Windows Script Component                                         text/scriptlet
    SEARCHCONNECTOR-MS  Search Connector Folder                                          application/windows-search-connector+xml
    SEARCH-MS         Saved Search                                                     
    SFCACHE           ReadyBoost Cache File                                            
    SHTML             SHTML File                                                       text/html
    SLDM               Microsoft PowerPoint                    application/vnd.ms-powerpoint.slide.macroEnabled.12
    SLDX               Microsoft PowerPoint                                       application/vnd.openxmlformats-officedocument.presentationml.slide
    SLK                  Microsoft Excel SLK                        application/vnd.ms-excel
    SLUPKG-MS         XrML Digital License Package                                     application/x-ms-license
    SND               AU Format Sound                                                  audio/basic
    SOLITAIRESAVE-MS  .SolitaireSave-ms                                                
    SPC               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    SPIDERSOLITAIRESAVE-MS  .SpiderSolitaireSave-ms                                          
    SST               Microsoft Serialized Certificate Store                           application/vnd.ms-pki.certstore
    STL               Certificate Trust List                                           application/vnd.ms-pki.stl
    SYS               System file                                                      
    THEME             Windows Theme File                                               
    THEMEPACK         Windows Theme Pack                                               
    THMX               Microsoft Office                                            application/vnd.ms-officetheme
    TIF               TIF File                                                         image/tiff
    TIFF              TIFF File                                                        image/tiff
    TS                MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TTC               TrueType Collection Font file                                    
    TTF               TrueType Font file                                               
    TTS               MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TXT               Text Document                                                    text/plain
    UDL               Microsoft Data Link                                              
    URL               URL File                                                         
    UXDC              UXDC File                                                        
    VBE               VBScript Encoded File                                            
    VBS               VBScript Script File                                             
    VCF                vCard                                                       text/x-vcard
    VCS                vCalendar                                                   
    VXD               Virtual Device Driver                                            
    WAB               Address Book File                                                
    WAV               Wave Sound                                                       audio/wav
    WAX               Windows Media Audio shortcut                                     audio/x-ms-wax
    WBCAT             Windows Backup Catalog File                                      
    WBK                  Microsoft Word                          application/msword
    WCX               Workspace Configuration File                                     
    WDP               Windows Media Photo                                              image/vnd.ms-photo
    WEBARCHIVE        WEBARCHIVE File                                                  
    WEBPNP            Web Point And Print File                                         
    WIZ                Microsoft Word                                            application/msword
    WIZHTML           Microsoft Access HTML Template                                   
    WLL               WLL File                                                         
    WM                Windows Media Audio/Video file                                   video/x-ms-wm
    WMA               Windows Media Audio file                                         audio/x-ms-wma
    WMD               Windows Media Player Download Package                            application/x-ms-wmd
    WMDB              Windows Media Library                                            
    WMF               WMF File                                                         
    WMS               Windows Media Player Skin File                                   
    WMV               Windows Media Audio/Video file                                   video/x-ms-wmv
    WMX               Windows Media Audio/Video playlist                               video/x-ms-wmx
    WMZ               Windows Media Player Skin Package                                application/x-ms-wmz
    WPL               Windows Media playlist                                           application/vnd.ms-wpl
    WSC               Windows Script Component                                         text/scriptlet
    WSF               Windows Script File                                              
    WSH               Windows Script Host Settings File                                
    WTV               Windows Recorded TV Show                                         
    WTX               Text Document                                                    
    WVX               Windows Media Audio/Video playlist                               video/x-ms-wvx
    XAML              Windows Markup File                                              application/xaml+xml
    XBAP              XAML Browser Application                                         application/x-ms-xbap
    XEVGENXML         XEVGENXML File                                                   
    XHT               XHT File                                                         application/xhtml+xml
    XHTML             XHTML File                                                       application/xhtml+xml
    XLA                Microsoft Excel                                       application/vnd.ms-excel
    XLAM               Microsoft Excel                                       application/vnd.ms-excel.addin.macroEnabled.12
    XLD                 Microsoft Excel 5.0                                application/vnd.ms-excel
    XLK                  Microsoft Excel                             application/vnd.ms-excel
    XLL                Microsoft Excel XLL                                   application/vnd.ms-excel
    XLM                Microsoft Excel 4.0                                       application/vnd.ms-excel
    XLS                Microsoft Excel 97-2003                                     application/vnd.ms-excel
    XLSB                Microsoft Excel                                    application/vnd.ms-excel.sheet.binary.macroEnabled.12
    XLSHTML            Microsoft Excel   HTML                          
    XLSM               Microsoft Excel                          application/vnd.ms-excel.sheet.macroEnabled.12
    XLSMHTML          XLSMHTML File                                                    
    XLSX               Microsoft Excel                                             application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
    XLT                Microsoft Excel                                           application/vnd.ms-excel
    XLTHTML            Microsoft Excel   HTML                            
    XLTM               Microsoft Excel                        application/vnd.ms-excel.template.macroEnabled.12
    XLTX               Microsoft Excel                                           application/vnd.openxmlformats-officedocument.spreadsheetml.template
    XLW                 Microsoft Excel                                  application/vnd.ms-excel
    XLXML              Microsoft Excel   XML                               
    XML               XML Document                                                     text/xml
    XPS               XPS Document                                                     application/vnd.ms-xpsdocument
    XRM-MS            XrML Digital License                                             text/xml
    XSL               XSL Stylesheet                                                   text/xml
    ZFSENDTOTARGET    Compressed (zipped) Folder SendTo Target                         
    ZIP               Compressed (zipped) Folder                                       application/x-zip-compressed


--------[    ]--------------------------------------------------------------------------------------

  [ Windows Media Center ]

     :
                                                     Windows Media Center
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               MediaCenter.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Currency.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\ru-RU\gadget.xml

  [   - ]

     :
                                                       -
                                                   ,     .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                      (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                      .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Weather.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                          .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\ru-RU\gadget.xml


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       Service Pack 1
      Winlogon Shell                                    explorer.exe
          (UAC)  
                                   

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  Windows ]------------------------------------------------------------------------------------------

    (Automatic Update)                                                                             
       Windows (KB958488)                                                          20.02.2012


--------[  ]--------------------------------------------------------------------------------------------------

     Windows                              6.1.7600.16385  


--------[   ]--------------------------------------------------------------------------------------------

    Microsoft Windows Defender                6.1.7600.16385(win7_rtm.090713-1255)


--------[   ]--------------------------------------------------------------------------------------

     :
                                      ()
                            (UTC+04:00) -, 
                               
                                    

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   .
         (ISO 4217)                RUB
                                      123456789,00.
                         -123456789,00.

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\᫠\AppData\Roaming
    CommonProgramFiles(x86)   C:\Program Files (x86)\Common Files
    CommonProgramFiles        C:\Program Files (x86)\Common Files
    CommonProgramW6432        C:\Program Files\Common Files
    COMPUTERNAME              -
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\᫠
    LOCALAPPDATA              C:\Users\᫠\AppData\Local
    LOGONSERVER               \\-
    NUMBER_OF_PROCESSORS      2
    OS                        Windows_NT
    Path                      C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_ARCHITEW6432    AMD64
    PROCESSOR_IDENTIFIER      AMD64 Family 15 Model 107 Stepping 1, AuthenticAMD
    PROCESSOR_LEVEL           15
    PROCESSOR_REVISION        6b01
    ProgramData               C:\ProgramData
    ProgramFiles(x86)         C:\Program Files (x86)
    ProgramFiles              C:\Program Files (x86)
    ProgramW6432              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\4918~1\AppData\Local\Temp
    TMP                       C:\Users\4918~1\AppData\Local\Temp
    USERDOMAIN                ᫠-
    USERNAME                  ᫠
    USERPROFILE               C:\Users\᫠
    windir                    C:\Windows
    windows_tracing_flags     3
    windows_tracing_logfile   C:\BVTBin\Tests\installpackage\csilogfile.log


--------[   ]-------------------------------------------------------------------------------------------

    Flash Player                                Flash Player
    Nero BurnRights 10                            CD/DVD.
                                          Microsoft Outlook


--------[  ]-----------------------------------------------------------------------------------------------------

    C:            0         0      ?  ?
    E:            0         0      ?  ?


--------[   ]---------------------------------------------------------------------------------------------

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1
    CMCDLLNAME32=mapi32.dll
    CMC=1
    MAPIX=1
    MAPIXVER=1.0.0.1
    OLEMessaging=1
    [MCI Extensions.BAK]
    3g2=MPEGVideo
    3gp=MPEGVideo
    3gp2=MPEGVideo
    3gpp=MPEGVideo
    aac=MPEGVideo
    adt=MPEGVideo
    adts=MPEGVideo
    m2t=MPEGVideo
    m2ts=MPEGVideo
    m2v=MPEGVideo
    m4a=MPEGVideo
    m4v=MPEGVideo
    mod=MPEGVideo
    mov=MPEGVideo
    mp4=MPEGVideo
    mp4v=MPEGVideo
    mts=MPEGVideo
    ts=MPEGVideo
    tts=MPEGVideo

  [ hosts ]

    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\\AppData\Roaming
    Cache                        C:\Users\\AppData\Local\Microsoft\Windows\Temporary Internet Files
    CD Burning                   C:\Users\\AppData\Local\Microsoft\Windows\Burn\Burn
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\\Favorites
    Common Files (x86)           C:\Program Files (x86)\Common Files
    Common Files                 C:\Program Files (x86)\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\\AppData\Roaming\Microsoft\Windows\Cookies
    Desktop                      C:\Users\\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\\AppData\Local
    My Documents                 C:\Users\\Documents
    My Music                     C:\Users\\Music
    My Pictures                  C:\Users\\Pictures
    My Video                     C:\Users\\Videos
    NetHood                      C:\Users\\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\
    Program Files (x86)          C:\Program Files (x86)
    Program Files                C:\Program Files (x86)
    Programs                     C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System (x86)                 C:\Windows\SysWOW64
    System                       C:\Windows\system32
    Temp                         C:\Users\4918~1\AppData\Local\Temp\
    Templates                    C:\Users\\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                         2012-02-19 21:46:01                                  WinMgmt                         
                       2012-02-19 21:46:01  LOCAL SERVICE                   Microsoft-Windows-RPC-Events    11:     ,   .  
               1          2012-02-19 21:46:06                                  Windows Search Service          1008:  Windows Search        (:   ).    
                       2012-02-19 21:47:21                           Microsoft-Windows-User Profiles Service  1530: C:\Windows\System32\profsvc.dll
                 100        2012-02-20 07:12:00                                  Application Error               1000:   : svchost.exe_ProfSvc, : 6.1.7600.16385,  : 0x4a5bc3c1    : ntdll.dll, : 6.1.7601.17514,   0x4ce7c8f9   : 0xc0000005   : 0x0000000000026297    : 0x314     : 0x01ccef7d3960e680    : C:\Windows\system32\svchost.exe    : C:\Windows\SYSTEM32\ntdll.dll   : a6f1c200-5b70-11e1-899b-001fc6c330e5
                 100        2012-02-20 07:12:49                                  Application Error               1000:   : svchost.exe_BITS, : 6.1.7600.16385,  : 0x4a5bc3c1    : ntdll.dll, : 6.1.7601.17514,   0x4ce7c8f9   : 0xc0000005   : 0x0000000000053332    : 0xb70     : 0x01ccef7d6cb93000    : C:\Windows\system32\svchost.exe    : C:\Windows\SYSTEM32\ntdll.dll   : c4827bc0-5b70-11e1-899b-001fc6c330e5
                         2012-02-20 07:13:01                                  WinMgmt                         
                         2012-02-20 07:19:31                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 07:19:31                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 07:19:31                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 07:19:31                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 07:19:46                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 07:19:46                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 07:19:46                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 07:19:46                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 07:19:46                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2012-02-20 07:22:28                                  Application Error               1000:   : Explorer.EXE, : 6.1.7601.17514,  : 0x4ce7a144    : ntdll.dll, : 6.1.7601.17514,   0x4ce7c8f9   : 0xc0000005   : 0x0000000000053332    : 0x6a0     : 0x01ccef7d3fa08280    : C:\Windows\Explorer.EXE    : C:\Windows\SYSTEM32\ntdll.dll   : 1d2beb84-5b72-11e1-899b-001fc6c330e5
                         2012-02-20 14:44:32                                  WinMgmt                         
                         2012-02-20 15:10:38                                  WinMgmt                         
                 1          2012-02-20 15:11:26                                  Windows Search Service          7040:         {=1300}.          .  :  "Windows",  "SystemIndex"  :     .   0xc0041801 (0xc0041801)   
                 1          2012-02-20 15:11:26                                  Windows Search Service          7042:   Windows Search  -   : The catalog is corrupt.  :  "Windows",  "SystemIndex"  :     .   0xc0041801 (0xc0041801)   
               1          2012-02-20 15:11:39                                  Windows Search Service          1008:  Windows Search        (:  ).    
                 1          2012-02-20 15:33:49                                  Windows Search Service          7040:         {=2305}.          .  :  "Windows",  "SystemIndex"  :     .   0xc0041801 (0xc0041801)   
                 1          2012-02-20 15:33:49                                  Windows Search Service          7042:   Windows Search  -   : The catalog is corrupt.  :  "Windows",  "SystemIndex"  :     .   0xc0041801 (0xc0041801)   
                 3          2012-02-20 15:33:49                                  Windows Search Service          3029:       <Search.TripoliIndexer>.  :  "Windows",  "SystemIndex"  :      .  (HRESULT : 0xc0041800) (0xc0041800)   
                 3          2012-02-20 15:33:49                                  Windows Search Service          3028:       .  :  "Windows",  "SystemIndex"  :      .  (HRESULT : 0xc0041800) (0xc0041800)   
                 3          2012-02-20 15:33:49                                  Windows Search Service          3058:    .  :  "Windows"  :      .  (HRESULT : 0xc0041800) (0xc0041800)   
                 3          2012-02-20 15:33:49                                  Windows Search Service          7010:   .  :      .  (HRESULT : 0xc0041800) (0xc0041800)   
                 3          2012-02-20 15:33:49                                  Windows Search Service          7040:         {=4400}.          .  :     .  (HRESULT : 0xc0041801) (0xc0041801)   
                 3          2012-02-20 15:33:49                                  Windows Search Service          7042:   Windows Search  -   : The catalog is corrupt.  :     .  (HRESULT : 0xc0041801) (0xc0041801)   
               1          2012-02-20 15:34:20                                  Windows Search Service          1008:  Windows Search        (:  ).    
                         2012-02-20 15:35:18                                  WinMgmt                         
                         2012-02-20 16:55:15                                  WinMgmt                         
                         2012-02-20 16:59:27                         Microsoft-Windows-LoadPerf      3002:            .  : ??.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 16:59:28                         Microsoft-Windows-LoadPerf      3002:            .  : ?0A*???.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 16:59:28                         Microsoft-Windows-LoadPerf      3002:            .  : ?&.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 16:59:28                         Microsoft-Windows-LoadPerf      3002:            .  : ?^AX.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:02:15                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:02:16                         Microsoft-Windows-LoadPerf      3002:            .  :  oft??E? Fra??w? k\v??0? 031??_? two??i? Per??o? ter??h? .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:02:40                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 17:02:54                         Microsoft-Windows-LoadPerf      3002:            .  : ? .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:02:55                         Microsoft-Windows-LoadPerf      3002:            .  : ?_A]???.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:02:55                         Microsoft-Windows-LoadPerf      3002:            .  : ?+.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:02:55                         Microsoft-Windows-LoadPerf      3002:            .  : ?9A2???.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:03:12                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:03:13                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:03:14                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
               1          2012-02-20 17:03:14                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2012-02-20 17:03:19                         Microsoft-Windows-LoadPerf      3002:            .  : B.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:03:19                         Microsoft-Windows-LoadPerf      3002:            .  : B.    (DWORD)        ,       (DWORD)        .  
               1          2012-02-20 17:03:19                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2012-02-20 17:04:39                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:04:40                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:04:41                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
               1          2012-02-20 17:04:41                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2012-02-20 17:04:45                         Microsoft-Windows-LoadPerf      3002:            .  : B.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:04:45                         Microsoft-Windows-LoadPerf      3002:            .  : B.    (DWORD)        ,       (DWORD)        .  
               1          2012-02-20 17:04:45                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2012-02-20 17:04:46                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 17:05:12                         Microsoft-Windows-LoadPerf      3002:            .  : ?g.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:05:12                         Microsoft-Windows-LoadPerf      3002:            .  : ?3.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:06:42                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:07:01                         Microsoft-Windows-LoadPerf      3002:            .  : ?(.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:07:01                         Microsoft-Windows-LoadPerf      3002:            .  : ?LAJ???.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:07:01                         Microsoft-Windows-LoadPerf      3002:            .  : ?9.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:07:01                         Microsoft-Windows-LoadPerf      3002:            .  : ?VAO???.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:07:15                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:07:15                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:07:16                         Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
               1          2012-02-20 17:07:16                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2012-02-20 17:07:19                         Microsoft-Windows-LoadPerf      3002:            .  : B.    (DWORD)        ,       (DWORD)        .  
                         2012-02-20 17:07:19                         Microsoft-Windows-LoadPerf      3002:            .  : B.    (DWORD)        ,       (DWORD)        .  
               1          2012-02-20 17:07:19                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2012-02-20 17:09:12                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 17:10:03                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 17:10:08                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                         2012-02-20 17:10:14                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
               3          2012-02-20 17:10:19                                  Windows Search Service          3036:     <file:C:/Program Files (x86)/Microsoft Office/Office14/Visio Content/> .  :  "",  "SystemIndex"  :    .  (HRESULT : 0x80041201) (0x80041201)   
                         2012-02-20 17:10:20                                  WinMgmt                         
                         2012-02-20 17:10:43                                  Microsoft-Windows-CAPI2         4107:       CAB-    <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>   /                 .  .  
                 100        2012-02-20 18:06:00                                  Application Error               1000:   : svchost.exe_RpcEptMapper, : 6.1.7600.16385,  : 0x4a5bc3c1    : ntdll.dll, : 6.1.7601.17514,   0x4ce7c8f9   : 0xc0000005   : 0x000000000005489e    : 0x304     : 0x01ccefcea783afd4    : C:\Windows\system32\svchost.exe    : C:\Windows\SYSTEM32\ntdll.dll   : 03ed6e7c-5bcc-11e1-bb3f-001fc6c330e5
                         2012-02-20 18:14:27                                  WinMgmt                         
                         2012-02-20 18:54:38                                  WinMgmt                         
                 100        2012-02-20 19:13:53                                  Application Error               1000:   : svchost.exe_p2pimsvc, : 6.1.7600.16385,  : 0x4a5bc3c1    : ntdll.dll, : 6.1.7601.17514,   0x4ce7c8f9   : 0xc0000005   : 0x0000000000025329    : 0x4b8     : 0x01ccefdf6861b100    : C:\Windows\System32\svchost.exe    : C:\Windows\SYSTEM32\ntdll.dll   : 7f99a384-5bd5-11e1-8a67-001fc6c330e5
                 100        2012-02-20 19:22:59                                  Application Error               1000:   : WebKit2WebProcess.exe, : 7534.52.7.3,  : 0x4eb0c4dc    : dnsapi.DLL, : 6.1.7601.17514,   0x4ce7b7e6   : 0xc0000005   : 0x00004624    : 0x138     : 0x01ccefdf7eaf1c54    : C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe    : C:\Windows\system32\dnsapi.DLL   : c4f641ac-5bd6-11e1-8a67-001fc6c330e5
                         2012-02-21 19:04:08                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2012-02-21 19:04:08                           Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                 16         2012-02-21 19:44:00                                  ATIeRecord                      16388: C:\Windows\System32\drivers\ati2erec.dll
                         2012-02-21 19:45:40                                  WinMgmt                         
                         2012-02-21 19:49:11                           Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-22 07:11:16                                  WinMgmt                         
                         2012-02-22 07:14:52                           Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                         2012-02-22 13:17:03                                  WinMgmt                         
                         2012-02-22 13:20:01                           Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
                 16         2012-02-22 14:29:09                                  ATIeRecord                      16388: C:\Windows\System32\drivers\ati2erec.dll
                         2012-02-22 14:33:48                                  WinMgmt                         
                         2012-02-22 14:36:34                           Microsoft-Windows-LoadPerf      3002:            .  :  .    (DWORD)        ,       (DWORD)        .  
      Audit Success   12288      2012-02-19 20:48:34                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x10c   :  C:\Windows\System32\svchost.exe     :  2012-02-19T17:48:32.820400000Z   :  2012-02-19T16:48:34.823655000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2012-02-19 20:48:34                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x10c   :  C:\Windows\System32\svchost.exe     :  2012-02-19T16:48:34.823655000Z   :  2012-02-19T16:48:34.823000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2012-02-19 20:48:34                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x10c   :  C:\Windows\System32\svchost.exe     :  2012-02-19T16:48:34.838600000Z   :  2012-02-19T16:48:34.838000000Z          .    Windows,    ,    .           .  
      Audit Success   12545      2012-02-19 20:48:59                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x72582      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-19 20:49:00                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-19 21:39:38                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-19 21:39:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x30cf8  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-556    :        :  Builtin    :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-547    :       :  Builtin    :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-551    :       :  Builtin    :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-552    :      :  Builtin    :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-555    :         :  Builtin    :      SAM:        SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:41                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:42                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-569    :       :  Builtin    :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:39:42                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   12544      2012-02-19 21:39:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:39:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:39:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:39:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:40:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-19 21:40:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-19 21:40:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:40:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-19 21:40:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-19 21:40:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:40:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:40:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:40:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:40:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-19 21:40:06                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2012-02-19 21:40:07                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-19 21:40:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3ff6f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13824      2012-02-19 21:42:06                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-500     :  Administrator     :  37L4247F27-25     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  0x211     UAC:  0x211      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2012-02-19 21:42:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:42:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:42:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:42:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:43:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-19 21:43:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247F27-25$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:43:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-19 21:43:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2012-02-19 21:43:24                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-19 21:44:20                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-19 21:44:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2012-02-19 21:44:21                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x8c11  
      Audit Success   12544      2012-02-19 21:44:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-19 21:44:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:44:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-19 21:44:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:44:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-19 21:44:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-19 21:44:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:44:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-19 21:44:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-19 21:44:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:45:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:45:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:45:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:45:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-19 21:45:21                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2012-02-19 21:45:22                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-19 21:45:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x228f5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-569     :  Builtin      :        :       :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-573     :  Builtin      : Event Log Readers      :        :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-500     :  Administrator     :  -     :      SAM: Administrator    :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 21.11.2010 6:57:24       :  %%1794     : 513    : -     UAC:  0x211     UAC:  0x211      : -    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-500     :  -      : Administrator      :      :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-500     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 21.11.2010 6:57:24       :  %%1794     : 513    : -     UAC:  0x211     UAC:  0x211      : -    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-501     :  Guest     :  -     :      SAM: Guest    :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x215     UAC:  0x215      : -    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-501     :  -      : Guest      :      :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-501     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x215     UAC:  0x215      : -    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-544     :  Builtin      : Administrators      :      :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-545     :  Builtin      : Users      :      :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-546     :  Builtin      : Guests      :      :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-551     :  Builtin      :        :       :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-552     :  Builtin      :       :      :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-555     :  Builtin      :          :         :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-556     :  Builtin      :         :        :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-547     :  Builtin      :        :       :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-558     :  Builtin      : Performance Monitor Users      :        :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-559     :  Builtin      : Performance Log Users      :        :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-562     :  Builtin      : Distributed COM Users      :  DCOM     :   :  -  
      Audit Success   13824      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-568     :  Builtin      : IIS_IUSRS      : IIS_IUSRS     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin     :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-573    :  Event Log Readers    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-573    :        :  Builtin     :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :  Administrators    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin     :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :  Users    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :      :  Builtin     :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-546    :  Guests    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-546    :      :  Builtin     :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin     :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin     :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin     :      SAM:        SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin     :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin     :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-558    :  Performance Monitor Users    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-558    :        :  Builtin     :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-559    :  Performance Log Users    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-559    :        :  Builtin     :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-562    :  Distributed COM Users    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-562    :   DCOM    :  Builtin     :      SAM:  DCOM    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-568    :  IIS_IUSRS    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-568    :  IIS_IUSRS    :  Builtin     :      SAM: IIS_IUSRS    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:45:27                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   12288      2012-02-19 21:45:34                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    : 0x330   :  C:\Windows\System32\oobe\msoobe.exe     :  2012-02-19T17:45:34.415200000Z   :  2012-02-19T17:45:34.306000000Z          .    Windows,    ,    .           .  
      Audit Success   12290      2012-02-19 21:45:50                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-19 21:45:50                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   13824      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  4720:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x0     UAC:  0x15      :     %%2080    %%2082    %%2084    : %%1793    SID:  -    :  %%1797     :   Privileges  -  
      Audit Success   13824      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  4722:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -  
      Audit Success   13824      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x15     UAC:  0x14      :     %%2048    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13826      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-21-1704761906-3848391464-3404229172-1000    :  HomeUsers    :  -    :      SAM: HomeUsers    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1000    :  HomeUsers    :  -     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  4728:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :  -    :    :  S-1-5-21-1704761906-3848391464-3404229172-513    :  None    :  -     :   :  -  
      Audit Success   13826      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  4732:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :  -    :    :  S-1-5-32-545    :      :  Builtin     :   :  -  
      Audit Success   13826      2012-02-19 21:46:02                                  Microsoft-Windows-Security-Auditing  4732:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :  -    :    :  S-1-5-21-1704761906-3848391464-3404229172-1000    :  HomeUsers    :  -     :   :  -  
      Audit Success   12290      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2481    : 0x0  
      Audit Success   12290      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2459    : 0x0  
      Audit Success   12292      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2464    : 0x0  
      Audit Success   12292      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2464    : 0x0  
      Audit Success   12292      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   13826      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  4732:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :  -    :    :  S-1-5-32-544    :      :  Builtin     :   :  -  
      Audit Success   13826      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  4732:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-500     :  -    :    :  S-1-5-21-1704761906-3848391464-3404229172-1000    :  HomeUsers    :  -     :   :  -  
      Audit Success   13826      2012-02-19 21:46:03                                  Microsoft-Windows-Security-Auditing  4733:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :  -    :    :  S-1-5-32-545    :      :  Builtin     :   :  -  
      Audit Success   13569      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4717:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :     :  S-1-5-21-1704761906-3848391464-3404229172-1002     :     :  SeDenyInteractiveLogonRight  
      Audit Success   13569      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4717:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :     :  S-1-5-21-1704761906-3848391464-3404229172-1002     :     :  SeDenyBatchLogonRight  
      Audit Success   13824      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4720:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  HomeGroupUser$     :  -    :      SAM: HomeGroupUser$    :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x0     UAC:  0x15      :     %%2080    %%2082    %%2084    : %%1793    SID:  -    :  %%1797     :   Privileges  -  
      Audit Success   13824      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4722:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  HomeGroupUser$     :  -  
      Audit Success   13824      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  HomeGroupUser$     :  -     :      SAM: HomeGroupUser$    :  HomeGroupUser$     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 19.02.2012 20:46:04       :  %%1794     : 513    : -     UAC:  0x15     UAC:  0x210      :     %%2048    %%2050    %%2089    : -    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4724:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  HomeGroupUser$     :  -  
      Audit Success   13824      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x14     UAC:  0x214      :     %%2089    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  HomeGroupUser$     :  -     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   13824      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 19.02.2012 20:46:04       :  %%1794     : 513    : -     UAC:  0x214     UAC:  0x214      : -    : -    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4724:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -  
      Audit Success   13826      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4728:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  -    :    :  S-1-5-21-1704761906-3848391464-3404229172-513    :  None    :  -     :   :  -  
      Audit Success   13826      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4732:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  -    :    :  S-1-5-21-1704761906-3848391464-3404229172-1000    :  HomeUsers    :  -     :   :  -  
      Audit Success   13826      2012-02-19 21:46:04                                  Microsoft-Windows-Security-Auditing  4733:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  -    :    :  S-1-5-21-1704761906-3848391464-3404229172-1000    :  HomeUsers    :  -     :   :  -  
      Audit Success   13826      2012-02-19 21:46:05                                  Microsoft-Windows-Security-Auditing  4732:       .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1704761906-3848391464-3404229172-1002     :  -    :    :  S-1-5-21-1704761906-3848391464-3404229172-1000    :  HomeUsers    :  -     :   :  -  
      Audit Success   12544      2012-02-19 21:46:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:46:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:46:14                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x18c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-19 21:46:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x38ee6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x18c    :  C:\Windows\System32\winlogon.exe      :     : WIN-TV6IAS601OM     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-19 21:46:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x39a8e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x18c    :  C:\Windows\System32\winlogon.exe      :     : WIN-TV6IAS601OM     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:46:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x38ee6    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-19 21:47:21                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x39a8e      ,   .  ,  ,  .        .  
      Audit Success   12544      2012-02-19 21:47:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0xb68    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-19 21:47:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x71e7f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0xb68    :  C:\Windows\System32\winlogon.exe      :     : WIN-TV6IAS601OM     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-19 21:47:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x72582   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0xb68    :  C:\Windows\System32\winlogon.exe      :     : WIN-TV6IAS601OM     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:47:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x71e7f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-19 21:47:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-TV6IAS601OM$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-19 21:47:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2012-02-20 07:10:38                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-20 07:10:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 07:10:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7f08  
      Audit Success   12544      2012-02-20 07:10:46                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x19c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-20 07:10:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x11c96   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x19c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:10:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x11cbc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x19c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:10:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x11c96    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 07:10:47                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-20 07:10:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:10:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 07:10:48                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-20 07:10:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18b7a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:10:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:10:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 07:11:13                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 07:11:13                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 07:11:25                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-20 07:11:25                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 07:11:25                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 07:12:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:12:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-20 07:12:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18b7a     :   3          .           " ".      ,       .  
      Audit Success   12544      2012-02-20 07:12:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:12:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x82dc0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:12:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 07:12:25                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 07:12:25                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12545      2012-02-20 07:12:51                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x82dc0     :   3          .           " ".      ,       .  
      Audit Success   12544      2012-02-20 07:12:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:12:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 07:12:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:12:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 07:12:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x92f06   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12288      2012-02-20 07:14:04                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x3e4   :  C:\Windows\System32\svchost.exe     :  2012-02-20T03:14:04.299600000Z   :  2012-02-20T03:14:04.299000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2012-02-20 07:16:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 07:16:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:16:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 07:16:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 07:17:08                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x9c4    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x103f03  
      Audit Success   13568      2012-02-20 07:17:08                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x9c4    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x103f03  
      Audit Success   12544      2012-02-20 07:19:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:19:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 07:19:47                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x9c4    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x16e6c6  
      Audit Success   13568      2012-02-20 07:19:47                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x9c4    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x16e6c6  
      Audit Success   12544      2012-02-20 07:22:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:22:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 07:24:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:24:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 07:24:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 07:24:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-20 07:30:01                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x11cbc      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-20 07:30:02                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-20 14:42:48                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-20 14:42:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2012-02-20 14:42:48                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7b75  
      Audit Success   12544      2012-02-20 14:42:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 14:42:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 14:42:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 14:42:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 14:42:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 14:42:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 14:42:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 14:42:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 14:42:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 14:42:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 14:42:57                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-20 14:42:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 14:42:57                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-20 14:42:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16eae   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 14:42:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16ef2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 14:42:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 14:42:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16eae    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 14:42:58                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-20 14:42:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1b36e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 14:43:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 14:43:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 14:43:37                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 14:43:37                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 14:43:48                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-20 14:43:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 14:43:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 14:44:49                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 14:44:49                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 14:44:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 14:44:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 14:49:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 14:49:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2012-02-20 15:08:56                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-20 15:08:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2012-02-20 15:08:56                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x791b  
      Audit Success   12544      2012-02-20 15:09:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:09:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:09:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:09:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:09:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:09:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2012-02-20 15:09:04                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2012-02-20 15:09:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:09:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:09:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x208    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-20 15:09:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16857   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:09:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x1687d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:09:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:09:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:09:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16857    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 15:09:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-20 15:09:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:09:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 15:09:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-20 15:09:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1d3cc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:09:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:09:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:09:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:09:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 15:09:52                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 15:09:52                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 15:10:03                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-20 15:10:04                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 15:10:04                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 15:11:04                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 15:11:04                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 15:11:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:11:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:11:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:11:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:26:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:26:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:26:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:26:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:26:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:26:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 15:26:52                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x140    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1ef5b0  
      Audit Success   13568      2012-02-20 15:26:52                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x140    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1ef5b0  
      Audit Success   12544      2012-02-20 15:27:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:27:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-20 15:28:36                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x1687d      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-20 15:28:37                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-20 15:33:36                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-20 15:33:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2012-02-20 15:33:36                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x80b7  
      Audit Success   12544      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:33:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 15:33:39                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-20 15:33:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:33:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-20 15:33:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x17731   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:33:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x17764   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:33:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:33:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x17731    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 15:33:40                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-20 15:33:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1d356   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:33:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:33:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:33:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:33:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:33:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:33:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:34:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:34:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:34:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:34:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:34:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:34:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:34:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:34:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:34:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:34:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:34:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:34:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:34:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:34:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:34:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:34:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:34:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:34:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:34:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:34:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:34:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:34:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2012-02-20 15:34:26                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x17764      :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12290      2012-02-20 15:34:31                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 15:34:31                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 15:34:43                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-20 15:34:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 15:34:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 15:35:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:35:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 15:35:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 15:35:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 15:52:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:52:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:52:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:52:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 15:53:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 15:53:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:53:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 15:53:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 15:53:21                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x540    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xfdbd6  
      Audit Success   13568      2012-02-20 15:53:21                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x540    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xfdbd6  
      Audit Success   12544      2012-02-20 15:58:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 15:58:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 16:43:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:43:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:43:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:43:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 16:43:52                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x998    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1dcd73  
      Audit Success   13568      2012-02-20 16:43:52                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x998    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1dcd73  
      Audit Success   12544      2012-02-20 16:44:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:44:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 16:44:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:44:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13569      2012-02-20 16:44:56                                  Microsoft-Windows-Security-Auditing  4717:       .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x17731      :     :  S-1-5-32     :     :  SeServiceLogonRight  
      Audit Success   12544      2012-02-20 16:45:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:45:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-20 16:48:03                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x17764      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-20 16:48:05                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-20 16:51:32                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-20 16:51:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2012-02-20 16:51:32                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x829b  
      Audit Success   12544      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:51:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 16:51:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:51:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x238    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-20 16:51:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x188bc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:51:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x188f4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x238    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:51:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:51:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x188bc    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 16:51:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:51:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 16:51:40                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2012-02-20 16:51:40                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-20 16:51:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x23009   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:52:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:52:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 16:52:16                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 16:52:16                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 16:52:28                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-20 16:52:29                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 16:52:29                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 16:52:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2012-02-20 16:52:29                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x188f4      ,   .  ,  ,  .        .  
      Audit Success   12548      2012-02-20 16:52:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2012-02-20 16:52:31                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-20 16:53:33                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-20 16:53:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:53:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:53:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:53:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:53:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 16:53:33                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x84bf  
      Audit Success   12544      2012-02-20 16:53:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:53:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:53:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:53:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:53:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:53:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 16:53:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:53:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 16:53:36                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-20 16:53:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16d99   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:53:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16dc3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:53:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16d99    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 16:53:41                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-20 16:53:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:53:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 16:53:42                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-20 16:53:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x21610   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:53:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:53:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 16:54:12                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 16:54:12                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 16:54:24                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-20 16:54:25                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 16:54:25                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 16:55:25                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 16:55:25                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 16:55:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:55:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 16:57:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:57:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 16:57:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 16:57:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:57:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 16:57:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 16:58:10                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x420    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x8b6f6  
      Audit Success   13568      2012-02-20 16:58:10                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x420    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x8b6f6  
      Audit Success   12544      2012-02-20 16:58:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 16:58:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 17:03:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 17:03:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 17:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 17:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 17:08:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 17:08:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 17:08:19                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x154    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x2d4bfa  
      Audit Success   13568      2012-02-20 17:08:19                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x154    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x2d4bfa  
      Audit Success   12544      2012-02-20 17:10:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 17:10:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 17:13:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 17:13:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 17:51:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 17:51:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 17:51:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 17:51:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 18:06:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:06:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2012-02-20 18:11:32                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-20 18:12:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-20 18:12:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2012-02-20 18:12:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7b28  
      Audit Success   12544      2012-02-20 18:12:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:12:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:12:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 18:12:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 18:12:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:12:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:12:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:12:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 18:12:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 18:12:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 18:13:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:13:00                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-20 18:13:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x1687e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:13:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x168b5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:13:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 18:13:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x1687e    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 18:13:10                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-20 18:13:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:13:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 18:13:11                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-20 18:13:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28a0c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:13:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:13:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 18:13:43                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 18:13:43                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 18:13:55                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-20 18:13:56                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 18:13:56                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 18:14:56                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 18:14:56                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 18:16:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:16:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-20 18:16:02                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x168b5      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-20 18:16:05                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-20 18:52:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-20 18:52:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:52:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:52:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:52:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 18:52:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-20 18:52:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x85b9  
      Audit Success   12544      2012-02-20 18:52:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:52:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:52:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:52:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 18:52:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 18:52:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 18:52:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:52:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-20 18:52:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15d22   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:52:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15d4c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:52:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-20 18:52:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15d22    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 18:53:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:53:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-20 18:53:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2012-02-20 18:53:11                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-20 18:53:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x26ed1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-20 18:53:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 18:53:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-20 18:53:40                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 18:53:40                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 18:53:52                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-20 18:53:52                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 18:53:52                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-20 18:54:53                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-20 18:54:53                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-20 19:13:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 19:13:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-20 19:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x20c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-20 19:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-20 20:10:24                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15d4c      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-20 20:10:25                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2012-02-21 18:59:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 18:59:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-21 18:59:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 18:59:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-21 19:02:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 19:02:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-21 19:02:12                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-21 19:02:12                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-21 19:02:21                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-21 19:02:22                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-21 19:02:22                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-21 19:03:22                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-21 19:03:22                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-21 19:05:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2012-02-21 19:05:32                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x16e63      ,   .  ,  ,  .        .  
      Audit Success   12548      2012-02-21 19:05:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2012-02-21 19:05:37                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-21 19:43:55                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-21 19:43:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2012-02-21 19:43:55                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7b32  
      Audit Success   12544      2012-02-21 19:43:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 19:43:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-21 19:43:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-21 19:43:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-21 19:43:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-21 19:43:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 19:43:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-21 19:43:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-21 19:43:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-21 19:43:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-21 19:43:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-21 19:43:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1d4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-21 19:43:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15ae4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-21 19:43:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15b0e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 19:43:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-21 19:43:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15ae4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-21 19:44:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-21 19:44:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 19:44:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-21 19:44:13                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-21 19:44:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2cd4d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-21 19:44:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 19:44:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-21 19:44:30                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-21 19:44:30                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-21 19:44:45                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-21 19:44:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-21 19:44:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-21 19:45:45                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-21 19:45:45                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-21 19:46:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-21 19:46:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-21 20:32:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xc67ea   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.1.2    :  49181       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-21 20:32:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xc6926   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.1.2    :  49186       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2012-02-21 20:32:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xc67ea     :   3          .           " ".      ,       .  
      Audit Success   12545      2012-02-21 20:32:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xc6926     :   3          .           " ".      ,       .  
      Audit Success   12545      2012-02-21 20:39:17                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15b0e      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-21 20:39:19                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-22 07:09:35                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-22 07:09:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 07:09:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 07:09:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-22 07:09:36                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x841d  
      Audit Success   12544      2012-02-22 07:09:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 07:09:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 07:09:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 07:09:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 07:09:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 07:09:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 07:09:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 07:09:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 07:09:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 07:09:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 07:09:40                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-22 07:09:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x1659a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 07:09:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x165c4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 07:09:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x1659a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-22 07:09:51                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-22 07:09:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 07:09:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-22 07:09:56                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-22 07:09:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2ca4c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 07:09:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 07:09:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-22 07:10:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 07:10:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-22 07:10:27                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-22 07:10:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 07:10:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-22 07:11:28                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 07:11:28                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-22 07:12:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 07:12:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-22 07:24:23                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x165c4      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-22 07:24:25                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Success   12288      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-22 13:15:19                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x896f  
      Audit Success   12544      2012-02-22 13:15:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 13:15:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 13:15:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x23c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-22 13:15:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x158dd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 13:15:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x1591e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x23c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 13:15:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x158dd    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 13:15:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 13:15:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 13:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 13:15:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-22 13:15:34                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-22 13:15:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2a7d6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12292      2012-02-22 13:15:37                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-22 13:15:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 13:15:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-22 13:15:56                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 13:15:56                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-22 13:16:09                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-22 13:16:09                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 13:16:09                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-22 13:17:09                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 13:17:09                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-22 13:17:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 13:17:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2012-02-22 13:20:26                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x1591e      ,   .  ,  ,  .        .  
      Audit Success   103        2012-02-22 13:20:28                                  Microsoft-Windows-Eventlog      1100: C:\Windows\System32\wevtsvc.dll
      Audit Failure   12290      2012-02-22 14:28:51                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume1\Windows\System32\drivers\afd.sys   
      Audit Failure   12290      2012-02-22 14:28:51                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume1\Windows\System32\drivers\afd.sys   
      Audit Success   12288      2012-02-22 14:28:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-22 14:28:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Failure   12290      2012-02-22 14:28:52                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume1\Windows\System32\drivers\afd.sys   
      Audit Failure   12290      2012-02-22 14:28:52                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume1\Windows\System32\drivers\afd.sys   
      Audit Success   12544      2012-02-22 14:28:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:28:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-22 14:28:52                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x816a  
      Audit Failure   12290      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume1\Windows\System32\drivers\afd.sys   
      Audit Failure   12290      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume1\Windows\System32\drivers\afd.sys   
      Audit Success   12544      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 14:29:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 14:29:10                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-22 14:29:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x120e1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:29:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x12138   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e8    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:29:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x120e1    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 14:29:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:29:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2012-02-22 14:29:12                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume1\Windows\System32\drivers\afd.sys   
      Audit Failure   12290      2012-02-22 14:29:12                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume1\Windows\System32\drivers\afd.sys   
      Audit Success   12288      2012-02-22 14:32:04                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2012-02-22 14:32:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:32:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:32:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:32:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 14:32:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-22 14:32:04                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x8c33  
      Audit Success   12544      2012-02-22 14:32:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:32:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:32:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:32:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 14:32:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 14:32:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2012-02-22 14:32:06                                  Microsoft-Windows-Eventlog      1101: C:\Windows\System32\wevtsvc.dll
      Audit Success   12544      2012-02-22 14:32:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x230    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2012-02-22 14:32:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15c2b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x230    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:32:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15c55   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x230    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:32:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1704761906-3848391464-3404229172-1001     :       :  -    :  0x15c2b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 14:32:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:32:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-22 14:32:17                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2012-02-22 14:32:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:32:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2012-02-22 14:32:22                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2012-02-22 14:32:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2506e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:32:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:32:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2012-02-22 14:32:52                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 14:32:52                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 7aa39d0f-d93c-41a1-944e-abf7af2a7cad    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4b3330a9019a5d29f82f7218934bf55d_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-22 14:33:04                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12290      2012-02-22 14:33:05                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 14:33:05                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12290      2012-02-22 14:34:05                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2012-02-22 14:34:05                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : {D5F04BF1-FC3F-415D-AF59-816473759958}    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\Keys\120102edbebf991ca00f127b4ac3ece7_6b126e50-a39b-4194-90dd-79fce5274aae   : %%2458    : 0x0  
      Audit Success   12544      2012-02-22 14:34:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:34:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2012-02-22 14:59:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2012-02-22 14:59:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2012-02-22 14:59:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2012-02-22 14:59:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2012-02-22 15:00:03                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xb3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1de435  
      Audit Success   13568      2012-02-22 15:00:03                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xb3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1de435  
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7034: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:06                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:52                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:52                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:52                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:12:52                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 07:13:06                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 07:13:06                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 07:14:06                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 07:14:06                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 07:14:06                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 07:14:06                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 07:14:52                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 07:17:52                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 07:17:52                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-20 15:09:04                                  EventLog                        6008:      13:58:22  ?20.?02.?2012  .  
                            2012-02-20 15:09:09                                  BugCheck                        
                    2          2012-02-20 15:09:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:09:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:09:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:14:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:14:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:14:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:14:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:14:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:14:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:15:20                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:41                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:19:46                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:22:56                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:24                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:28                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:28                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:28                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:30                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:30                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:31                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:32                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:33                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:33                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:33                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:33                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:25:34                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:02                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:17                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:17                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:17                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:17                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:17                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:51                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:51                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:51                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:51                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:51                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                          2012-02-20 15:26:51                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                          2012-02-20 15:26:51                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                          2012-02-20 15:26:51                           Ntfs                            130: C:\Windows\system32\drivers\ntfs.sys
                  2          2012-02-20 15:26:51                                  Ntfs                            134: C:\Windows\system32\drivers\ntfs.sys
                  2          2012-02-20 15:26:51                                  Ntfs                            134: C:\Windows\system32\drivers\ntfs.sys
                  2          2012-02-20 15:26:51                                  Ntfs                            134: C:\Windows\system32\drivers\ntfs.sys
                  2          2012-02-20 15:26:51                                  Ntfs                            134: C:\Windows\system32\drivers\ntfs.sys
                  2          2012-02-20 15:26:51                                  Ntfs                            134: C:\Windows\system32\drivers\ntfs.sys
                  2          2012-02-20 15:26:51                                  Ntfs                            134: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:52                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:52                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:52                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:52                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:26:52                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:03                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:03                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:05                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:06                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:06                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:06                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:11                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:11                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:11                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:11                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:13                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:15                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:16                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:16                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:16                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:20                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:20                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:20                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:20                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:22                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:23                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:23                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:23                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:25                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:26                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:29                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:29                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:29                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                    2          2012-02-20 15:27:50                                  Ntfs                            55: C:\Windows\system32\drivers\ntfs.sys
                            2012-02-20 15:33:49                                  Service Control Manager         7024: C:\Windows\system32\services.exe
                            2012-02-20 15:33:49                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 15:33:57                                  DCOM                            
                            2012-02-20 15:33:57                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:33:57                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:33:57                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:33:57                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:00                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:00                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:05                                  DCOM                            
                            2012-02-20 15:34:05                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:05                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:05                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:05                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:06                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:06                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:09                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:09                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:09                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:09                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:09                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:09                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:09                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:09                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:14                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:14                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:34:14                                  Service Control Manager         7009: C:\Windows\system32\services.exe
                            2012-02-20 15:34:14                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 15:35:41                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 16:55:43                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 18:06:00                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 18:06:00                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 18:11:07                                  BROWSER                         8007:        .    .  
                            2012-02-20 18:15:20                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 18:52:47                           Microsoft-Windows-Kernel-General  5:   .  
                            2012-02-20 18:55:19                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-20 19:13:55                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 19:13:55                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-20 19:13:55                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-21 18:59:58                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-21 18:59:58                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-21 18:59:58                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-21 18:59:58                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-21 18:59:58                                  Service Control Manager         7026: C:\Windows\system32\services.exe
                            2012-02-21 18:59:59                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-21 19:02:05                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                          2012-02-21 19:02:07  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     isatap.Home        DNS.  
                            2012-02-21 19:46:18                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-22 07:12:01                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-22 13:15:13                           Microsoft-Windows-Kernel-General  5:   .  
                          2012-02-22 13:17:32                                  BROWSER                         8021:           \\-  \Device\NetBT_Tcpip_{C2DF2DF7-FABB-406E-91EA-3EA7A8B03E24}.         : \\-    : \Device\NetBT_Tcpip_{C2DF2DF7-FABB-406E-91EA-3EA7A8B03E24}                .      ,   -   .      "".  
                            2012-02-22 13:17:40                                  Service Control Manager         7000: C:\Windows\system32\services.exe
                            2012-02-22 13:19:06                                  BROWSER                         8032:              \Device\NetBT_Tcpip_{C2DF2DF7-FABB-406E-91EA-3EA7A8B03E24}.     .  
                            2012-02-22 13:19:06                                  NetBT                           4321:  "WORKGROUP      :1d"       IP- 192.168.1.3.    IP- 192.168.1.2    ,    .  
                            2012-02-22 14:28:48                           Microsoft-Windows-Kernel-General  5:   .  
                            2012-02-22 14:29:08                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-22 14:29:08                                  Service Control Manager         7031: C:\Windows\system32\services.exe
                            2012-02-22 14:29:08                                  Service Control Manager         7032: C:\Windows\system32\services.exe
                            2012-02-22 14:29:08                                  Service Control Manager         7001: C:\Windows\system32\services.exe
                            2012-02-22 14:29:08                                  Service Control Manager         7001: C:\Windows\system32\services.exe
                            2012-02-22 14:29:10                                  Service Control Manager         7001: C:\Windows\system32\services.exe
                            2012-02-22 14:29:10                                  Service Control Manager         7001: C:\Windows\system32\services.exe
                            2012-02-22 14:32:07                                  BugCheck                        
                            2012-02-22 14:34:28                                  Service Control Manager         7000: C:\Windows\system32\services.exe


--------[   ]-------------------------------------------------------------------------------------------------------

      :
      Borland Database Engine                           -
      Borland InterBase Client                          -
      Easysoft ODBC-InterBase 6                         -
      Easysoft ODBC-InterBase 7                         -
      Firebird Client                                   -
      Jet Engine                                        4.00.9756.0
      MDAC                                              6.1.7601.17514 (win7sp1_rtm.101119-1850)
      ODBC                                              6.1.7601.17514 (win7sp1_rtm.101119-1850)
      MySQL Connector/ODBC                              -
      Oracle Client                                     -
      PsqlODBC                                          -
      Sybase ASE ODBC                                   -

     :
      Borland InterBase Server                          -
      Firebird Server                                   -
      Microsoft SQL Server                              -
      Microsoft SQL Server Compact Edition              -
      Microsoft SQL Server Express Edition              -
      MySQL Server                                      -
      Oracle Server                                     -
      PostgreSQL Server                                 -
      Sybase SQL Server                                 -


--------[  ODBC ]-----------------------------------------------------------------------------------------------

    Driver da Microsoft para arquivos texto (*.txt; *.csv)      odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Driver do Microsoft Access (*.mdb)                          odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.mdb
    Driver do Microsoft dBase (*.dbf)                           odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.dbf,*.ndx,*.mdx
    Driver do Microsoft Excel(*.xls)                            odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.xls
    Driver do Microsoft Paradox (*.db )                         odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.db
    Driver para o Microsoft Visual FoxPro                       vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Access dBASE Driver (*.dbf, *.ndx, *.mdx)         aceodbc.dll         14.0.4760.1000        *.dbf, *.ndx, *.mdx
    Microsoft Access Driver (*.mdb)                             odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.mdb
    Microsoft Access Driver (*.mdb, *.accdb)                    aceodbc.dll         14.0.4760.1000        *.mdb,*.accdb
    Microsoft Access Text Driver (*.txt, *.csv)                 aceodbc.dll         14.0.4760.1000        *.txt, *.csv
    Microsoft Access-Treiber (*.mdb)                            odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.mdb
    Microsoft dBase Driver (*.dbf)                              odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.dbf,*.ndx,*.mdx
    Microsoft dBase VFP Driver (*.dbf)                          vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft dBase-Treiber (*.dbf)                             odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.dbf,*.ndx,*.mdx
    Microsoft Excel Driver (*.xls)                              odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.xls
    Microsoft Excel Driver (*.xls, *.xlsx, *.xlsm, *.xlsb)      aceodbc.dll         14.0.4760.1000        *.xls,*.xlsx, *.xlsb
    Microsoft Excel-Treiber (*.xls)                             odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.xls
    Microsoft FoxPro VFP Driver (*.dbf)                         vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft ODBC for Oracle                                   msorcl32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  
    Microsoft Paradox Driver (*.db )                            odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.db
    Microsoft Paradox-Treiber (*.db )                           odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.db
    Microsoft Text Driver (*.txt; *.csv)                        odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Text-Treiber (*.txt; *.csv)                       odbcjt32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Visual FoxPro Driver                              vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Visual FoxPro-Treiber                             vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    SQL Server                                                  sqlsrv32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  


--------[    ]--------------------------------------------------------------------------------------------

    Core i7-2600            3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1            16392 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            15035 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            13903 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1            12355 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            11498 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9164 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8855 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1             8042 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 8004 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             7925 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 7896 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             7345 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7133 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             6997 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 6696 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             6330 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             6170 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             5932 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5643 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 5369 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             5293 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             4878 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             4838 /
    Athlon64 X2 5000+       2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2             4802 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 4701 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4569 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              4355 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             4116 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 3965 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3916 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             3805 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 3551 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 3516 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3348 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 3237 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 3141 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2890 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2835 /


--------[    ]---------------------------------------------------------------------------------------------

    Core i7-2600            3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1            18609 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            12546 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            12069 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9554 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1             9415 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8841 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1             7512 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7048 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             6734 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 6724 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             6340 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             5805 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             5693 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 5608 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 5594 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5358 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             4857 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4840 /
    Athlon64 X2 5000+       2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2             4652 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             4457 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             4228 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4178 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4111 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3805 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             3785 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 3631 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             3585 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             3264 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3152 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 2977 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 2818 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 2770 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2495 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 2459 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2345 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2325 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              1992 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             1655 /


--------[    ]----------------------------------------------------------------------------------------

    Core i7-2600            3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1            18352 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            14884 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            12622 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            11239 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1            10488 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1             9793 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9510 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             9425 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             8353 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             7112 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             6803 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             6564 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             6479 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             6200 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 6034 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 5933 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             5431 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 5423 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 4979 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             4760 /
    Athlon64 X2 5000+       2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2             4739 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4600 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4587 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 4226 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             4198 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4045 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             3898 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3668 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             3273 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 3146 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 3085 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 2966 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2895 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             2768 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2576 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              2518 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             2447 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 2381 /


--------[   ]---------------------------------------------------------------------------------------------

    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1       47.5 ns
    Core i7-2600            3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1       52.8 ns
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1       55.7 ns
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2       55.7 ns
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1       56.8 ns
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1       58.0 ns
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1       59.9 ns
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1       60.8 ns
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2       60.8 ns
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2       62.0 ns
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2       62.7 ns
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2       68.4 ns
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1       68.5 ns
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15           71.5 ns
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2       74.6 ns
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11           80.6 ns
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1        81.4 ns
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1       83.0 ns
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1       84.3 ns
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15           86.0 ns
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1       87.0 ns
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15           87.9 ns
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15           88.1 ns
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1        88.7 ns
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1       97.6 ns
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15          101.6 ns
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2      102.0 ns
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12          102.9 ns
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15          109.9 ns
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1      110.4 ns
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15          111.5 ns
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2      117.1 ns
    Athlon64 X2 5000+       2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2      123.9 ns
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12          126.9 ns
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7         146.4 ns
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11          148.8 ns
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2      159.9 ns
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1      225.6 ns


--------[ CPU Queen ]---------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1         56851
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         53516
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1         43777
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         42515
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             41590
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         37796
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         30777
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1         27260
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             26966
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         25446
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1         21971
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             21957
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         21900
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1         21438
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1         21224
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             19209
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         16090
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1         12582
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2         12127
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1         11237
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              9586
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2          9192
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              7523
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              7479
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             7297
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          7272
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1          5158
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1          4968
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           4877
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          4085
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              4021
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           3853
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12              3793
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          3514
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              3299
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          2813
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2          2571
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11              1838


--------[ CPU PhotoWorxx ]----------------------------------------------------------------------------------------------

    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1                 60906
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1                 53758
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1                 47731
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1                 47076
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1                 46577
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1                 34924
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1                 31080
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                     27264
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1                 24528
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1                 21974
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2                 20301
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2                 19258
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2                 14554
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                     12253
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                      9506
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1                  9474
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                      8654
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1                  8453
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                      8419
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1                  7398
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2                  7346
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                      6979
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                      5552
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                      5550
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1                   5473
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                      5093
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1                  4967
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2                  4899
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                     4434
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2                  4411
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1                  4367
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2                  4285
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1                   3765
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2                  3384
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2                  3211
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                      2507
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2                  2489
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                      2347


--------[ CPU ZLib ]----------------------------------------------------------------------------------------------------

    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1            348.9 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            339.7 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1            330.8 /
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1            272.0 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                266.9 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1            232.7 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            213.1 /
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1            208.7 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                178.8 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1            166.1 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2            146.7 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2            145.0 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                129.2 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                111.4 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2            106.9 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            102.5 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1            100.6 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             78.6 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             71.4 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             67.5 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 56.7 /
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2             55.8 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                54.9 /
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 54.6 /
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             45.1 /
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 44.0 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             39.3 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1             33.4 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             31.2 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 30.9 /
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              29.3 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              23.3 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             21.9 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 19.4 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 17.6 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 16.5 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             15.6 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             14.8 /


--------[ CPU AES ]-----------------------------------------------------------------------------------------------------

    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1        363627
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1        351623
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1        207934
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         78820
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         65665
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             61018
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         52978
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1         46845
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         41040
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             40660
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2         40397
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1         35888
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         32835
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         32587
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             29225
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1         27678
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             25463
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         23336
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1         18744
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1         16729
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2         16152
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2         13316
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15             12372
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11             10932
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2         10854
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7            10637
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              9961
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1          7552
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          7434
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           7122
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1          6531
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              5854
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           5659
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          5240
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              4394
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          4194
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11              3352
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12              1973


--------[ CPU Hash ]----------------------------------------------------------------------------------------------------

    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             4785 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 3611 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             3191 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1             3142 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             3101 /
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             2809 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2351 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2245 /
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1             2210 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             1992 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             1945 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1             1942 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 1684 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1             1661 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 1466 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             1441 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             1103 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1              981 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1              968 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2              925 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                  833 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                 812 /
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2              801 /
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                  730 /
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2              640 /
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                  574 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2              553 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2              495 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1              450 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                  445 /
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1               428 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1               336 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1              326 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2              306 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                  251 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                  248 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2              245 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                  161 /


--------[ FPU VP8 ]-----------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1                  3717
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1                  3459
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1                  3303
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                      3028
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1                  2805
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1                  2803
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1                  2789
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1                  2786
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2                  2323
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1                  2098
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2                  2087
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                      1824
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1                  1801
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1                  1795
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                      1739
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2                  1548
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                      1492
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2                  1127
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1                  1111
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1                   986
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                       891
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2                   787
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                       727
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                      686
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2                   659
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                       639
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1                   617
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2                   551
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2                   501
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                       464
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1                   455
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                       431
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1                    407
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1                    398
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2                   387
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                       375
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2                   300
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                       295


--------[ FPU Julia ]---------------------------------------------------------------------------------------------------

    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1         18415
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         18308
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1         18003
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         17674
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             15295
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         12206
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         11132
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1         10731
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              8951
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          8679
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          8205
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          8070
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          7607
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              6407
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              5593
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          5579
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          5549
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          3534
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              3074
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              2427
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             2370
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          2308
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              2182
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          2052
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          1976
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1          1716
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2          1673
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          1343
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              1302
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               956
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           914
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            896
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               886
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           796
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            702
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           640
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               588
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           514


--------[ FPU Mandel ]--------------------------------------------------------------------------------------------------

    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1          9763
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1          9317
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          8672
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1          8613
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              8067
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1          6212
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          5463
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          5397
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              4616
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          4418
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          4332
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          4178
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          3873
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              3305
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              2883
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          2840
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          2675
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1819
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              1624
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              1481
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             1447
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          1182
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              1126
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          1061
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1051
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1           874
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2           856
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               794
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2           688
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               494
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               476
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            458
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           427
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           407
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            360
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           328
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           263
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               194


--------[ FPU SinJulia ]------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          7467
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1          6993
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1          4665
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1          4658
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          4589
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              4137
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1          3101
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          2727
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              2590
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          2304
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          2266
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          2221
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          2209
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          1934
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              1855
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              1618
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          1421
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          1178
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1049
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1021
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11               959
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7              942
    2x Athlon64 X2 5000+    2600   Asus M2N                                                                nForce6100-430 Ext.   Dual DDR2-746         6-6-6-18 CR2           853
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15               834
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2           685
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15               633
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               516
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           506
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            457
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2           452
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1           437
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            359
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           327
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               277
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           262
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               205
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               203
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           131


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - Host Bridge (HyperTransport)
                  
      Offset 000:  DE 10 EA 03  06 00 B0 00  A1 00 00 05  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  43 10 34 82  08 DC 20 02  20 00 11 11  D0 00 00 00 
      Offset 050:  23 06 7F 00  03 00 00 00  00 00 03 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  06 36 00 00 
      Offset 070:  44 44 44 00  D0 09 00 00  11 00 00 00  11 11 88 00 
      Offset 080:  23 99 88 00  FA 00 64 0D  03 00 00 00  7F 00 00 00 
      Offset 090:  70 00 00 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  01 01 01 01  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  80 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  08 00 01 A8 
      Offset 0E0:  00 00 E0 FE  00 00 00 00  06 00 00 00  20 10 00 00 
      Offset 0F0:  F0 FF FF FF  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D01 F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - LPC Bridge
                  
      Offset 000:  DE 10 E0 03  0F 00 A0 00  A2 00 01 06  00 00 80 00 
      Offset 010:  01 09 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  43 10 34 82  00 00 D0 FE  FA 3E FF 00  FA 3E FF 00 
      Offset 050:  FA 3E FF 00  00 5A 62 02  00 00 00 05  2F 00 3C 01 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  10 00 FF FF  C5 80 00 00  00 00 45 19  04 00 06 00 
      Offset 080:  09 20 00 8D  01 08 00 00  F0 00 00 01  FF 00 00 00 
      Offset 090:  FF 7F 00 00  00 00 00 00  21 65 08 74  B9 0C 00 D0 
      Offset 0A0:  00 00 10 81  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  30 02 AF 02  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  50 41 00 FE  FD 03 00 B0 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  10 00 00 00  00 00 00 00 

    B00 D01 F01:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - SMBus Controller
                  
      Offset 000:  DE 10 EB 03  01 00 B0 00  A2 00 05 0C  00 00 80 00 
      Offset 010:  01 CC 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  01 06 00 00  01 07 00 00  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  0A 01 00 00 
      Offset 040:  43 10 34 82  01 00 02 C0  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  01 05 00 00  01 08 00 00  01 0D 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  01 20 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  D4 30 80 01  01 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  40 00 40 01  10 00 00 00  05 00 00 00  00 00 00 00 
      Offset 0E0:  80 10 04 00  04 40 00 07  80 2A 00 20  41 44 44 11 
      Offset 0F0:  02 FF 1E BF  01 00 00 80  10 00 00 00  00 00 00 00 

    B00 D01 F02:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - Shape/Trim
                  
      Offset 000:  DE 10 F5 03  00 04 A0 00  A2 00 00 05  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  43 10 34 82  00 00 00 00  10 02 80 10  10 00 10 10 
      Offset 050:  10 10 10 10  00 00 00 00  00 00 00 00  10 42 00 00 
      Offset 060:  0B 00 00 00  C0 1C 52 06  21 00 10 0A  00 00 63 00 
      Offset 070:  09 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 40 00  00 00 00 00  A0 18 00 00 
      Offset 090:  00 00 00 00  00 00 00 12  20 81 04 00  00 00 00 00 
      Offset 0A0:  00 14 00 06  00 00 00 00  00 00 00 00  01 00 00 00 
      Offset 0B0:  00 00 00 00  42 80 30 04  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D02 F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - OHCI USB 1.1 Controller
                  
      Offset 000:  DE 10 F1 03  06 00 B0 00  A3 10 03 0C  00 00 80 00 
      Offset 010:  00 F0 EF DF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  17 01 03 01 
      Offset 040:  43 10 34 82  01 00 02 FE  00 00 00 00  00 00 00 00 
      Offset 050:  01 00 00 00  1D 47 40 00  10 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D02 F01:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - EHCI USB 2.0 Controller
                  
      Offset 000:  DE 10 F2 03  06 00 B0 00  A3 20 03 0C  00 00 80 00 
      Offset 010:  00 EC EF DF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  16 02 03 01 
      Offset 040:  43 10 34 82  0A 80 98 20  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 01 00  00 60 18 85  83 12 0F 01  00 00 00 00 
      Offset 070:  00 00 08 00  00 10 20 80  89 3D B6 22  77 25 24 00 
      Offset 080:  01 00 02 FE  00 00 00 00  00 00 00 00  15 16 00 00 
      Offset 090:  00 01 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 00  00 20 00 C0  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 11 22 33  44 00 00 00  FF 03 00 00  00 00 00 00 
      Offset 0C0:  10 10 2D 0D  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  10 00 00 00  00 00 00 00 

    B00 D04 F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI-PCI Bridge
                  
      Offset 000:  DE 10 F3 03  07 04 B0 00  A1 01 04 06  00 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 01 01 40  D0 D0 80 22 
      Offset 020:  F0 FF 00 00  F0 FF 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  B8 00 00 00  00 00 00 00  00 00 02 06 
      Offset 040:  00 00 73 07  01 00 02 00  07 00 00 00  00 00 48 00 
      Offset 050:  00 00 00 00  00 00 00 00  FE 1F FF 1F  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 06 00 00  00 00 00 00  00 00 00 00  08 00 01 A8 
      Offset 090:  00 00 E0 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  04 00 00 00  00 00 00 00  01 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  FF FF 00 00  0D 8C 00 00  DE 10 84 CB 
      Offset 0C0:  DE 10 84 CB  07 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D06 F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - Parallel ATA Controller
                  
      Offset 000:  DE 10 EC 03  05 00 B0 00  A2 8A 01 01  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  A1 FF 00 00  00 00 00 00  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  00 00 03 01 
      Offset 040:  43 10 34 82  01 00 02 00  00 00 00 00  00 00 00 00 
      Offset 050:  02 F0 00 00  00 00 00 00  A8 A8 A8 20  7F 00 FF 20 
      Offset 060:  00 00 00 C5  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 90 F7 72  00 00 0C 30  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 01 01 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  10 00 00 00  00 00 00 00 

    B00 D07 F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - LAN Controller
                  
      Offset 000:  DE 10 EF 03  06 00 B0 00  A2 00 80 06  00 00 00 00 
      Offset 010:  00 D0 EF DF  01 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  14 01 01 14 
      Offset 040:  43 10 34 82  01 50 02 FE  00 01 00 00  08 00 00 20 
      Offset 050:  05 6C 86 01  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  FF 00 00 00  08 00 03 A8 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  10 00 00 00  42 01 00 00  00 00 00 00 

    B00 D08 F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller
                  
      Offset 000:  DE 10 F6 03  07 00 B0 00  A2 85 01 01  00 00 80 00 
      Offset 010:  01 C4 00 00  81 C0 00 00  01 C0 00 00  01 BC 00 00 
      Offset 020:  81 B8 00 00  00 C0 EF DF  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  14 01 03 01 
      Offset 040:  43 10 34 82  01 B0 02 00  00 00 00 00  00 00 00 00 
      Offset 050:  2F 68 08 00  00 00 00 00  00 00 00 20  40 00 00 20 
      Offset 060:  00 00 00 C7  41 0C 00 00  00 0F 06 42  00 00 00 00 
      Offset 070:  2C 78 C4 40  01 10 00 00  01 10 00 00  20 00 20 00 
      Offset 080:  00 00 00 40  00 F0 D9 BF  00 00 AC B8  DE DE D3 CF 
      Offset 090:  00 00 E6 38  00 00 00 00  06 00 06 10  00 00 01 01 
      Offset 0A0:  08 00 00 0F  00 00 00 00  00 00 00 00  33 31 00 02 
      Offset 0B0:  05 CC 84 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  0A 00 0A 00  08 00 03 A8 
      Offset 0D0:  09 00 00 B8  00 08 03 00  08 00 00 54  00 08 08 00 
      Offset 0E0:  00 00 40 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 0C 00  00 00 00 00 

    B00 D08 F01:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - SATA Controller
                  
      Offset 000:  DE 10 F6 03  07 00 B0 00  A2 85 01 01  00 00 80 00 
      Offset 010:  01 B8 00 00  81 B4 00 00  01 B4 00 00  81 B0 00 00 
      Offset 020:  01 B0 00 00  00 70 EF DF  00 00 00 00  43 10 34 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  15 02 03 01 
      Offset 040:  43 10 34 82  01 B0 02 00  00 00 00 00  00 00 00 00 
      Offset 050:  2F 68 08 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  41 0C 00 00  00 0F 06 42  00 00 00 00 
      Offset 070:  2C 78 C4 40  01 10 00 00  01 10 00 00  20 00 20 00 
      Offset 080:  00 00 00 00  DA 9D 80 55  00 00 CD 27  C6 FC DA 9D 
      Offset 090:  00 00 E8 33  00 00 00 00  06 00 06 10  00 00 01 01 
      Offset 0A0:  08 00 00 00  00 00 00 00  00 00 00 00  33 31 00 02 
      Offset 0B0:  05 CC 84 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  0A 00 0A 00  08 00 03 A8 
      Offset 0D0:  08 00 00 54  00 08 08 00  08 00 00 54  00 08 08 00 
      Offset 0E0:  00 00 40 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 0C 00  00 00 00 00 

    B00 D09 F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x16)
                  
      Offset 000:  DE 10 E8 03  07 04 10 00  A2 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 02 02 00  E1 E1 00 20 
      Offset 020:  F0 DF F0 DF  01 C0 F1 CF  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 00 1A 00 
      Offset 040:  0D 48 00 00  DE 10 00 00  01 50 02 F8  00 00 00 00 
      Offset 050:  05 60 93 00  0C 30 E0 FE  00 00 00 00  92 49 00 00 
      Offset 060:  08 80 01 A8  00 00 E0 FE  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  10 00 41 01  01 80 00 00  10 28 00 00  01 3D 11 00 
      Offset 090:  00 00 01 31  80 25 08 00  C0 01 48 01  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D0B F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1)
                  
      Offset 000:  DE 10 E9 03  04 04 10 00  A2 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 03 03 00  F1 01 00 00 
      Offset 020:  F0 FF 00 00  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 00 02 00 
      Offset 040:  0D 48 00 00  DE 10 00 00  01 50 02 F8  00 00 00 00 
      Offset 050:  05 60 93 00  0C 30 E0 FE  00 00 00 00  82 49 00 00 
      Offset 060:  08 80 01 A8  00 00 E0 FE  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  10 00 41 01  01 80 00 00  10 28 00 00  11 3C 11 01 
      Offset 090:  00 00 11 10  00 05 10 00  C0 01 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D0C F00:  nVIDIA nForce 6100-400/405/420/430 (MCP61) - PCI Express Root Port (x1)
                  
      Offset 000:  DE 10 E9 03  04 04 10 00  A2 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 04 04 00  F1 01 00 00 
      Offset 020:  F0 FF 00 00  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 00 02 00 
      Offset 040:  0D 48 00 00  DE 10 00 00  01 50 02 F8  00 00 00 00 
      Offset 050:  05 60 93 00  0C 30 E0 FE  00 00 00 00  72 49 00 00 
      Offset 060:  08 80 01 A8  00 00 E0 FE  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  10 00 41 01  01 80 00 00  10 28 00 00  11 3C 11 02 
      Offset 090:  00 00 11 10  00 05 18 00  C0 01 48 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F00:  AMD Hammer - HyperTransport Technology Configuration
                  
      Offset 000:  22 10 00 11  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  80 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 01 01 00  01 01 01 00  01 01 01 00  01 01 01 00 
      Offset 050:  01 01 01 00  01 01 01 00  01 01 01 00  01 01 01 00 
      Offset 060:  00 00 01 00  E4 00 00 00  20 C8 2E 0F  0C 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  08 00 01 21  20 00 11 11  22 06 75 80  02 00 00 00 
      Offset 090:  69 01 61 01  00 00 FF 00  07 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F01:  AMD Hammer - Address Map
                  
      Offset 000:  22 10 01 11  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  03 00 00 00  00 00 3F 01  00 00 00 00  01 00 00 00 
      Offset 050:  00 00 00 00  02 00 00 00  00 00 00 00  03 00 00 00 
      Offset 060:  00 00 00 00  04 00 00 00  00 00 00 00  05 00 00 00 
      Offset 070:  00 00 00 00  06 00 00 00  00 00 00 00  07 00 00 00 
      Offset 080:  03 00 E0 00  80 FF EF 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  03 0A 00 00  00 0B 00 00  03 00 C0 00  00 0B FE 00 
      Offset 0C0:  13 10 00 00  00 F0 FF 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  03 00 00 FF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  01 40 00 C0  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F02:  AMD Hammer - DRAM Controller
                  
      Offset 000:  22 10 02 11  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 00 00 00  01 02 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  E0 3D F8 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  46 00 00 00  00 00 00 00 
      Offset 080:  05 00 00 00  00 00 00 00  35 F3 FF 5D  20 13 22 00 
      Offset 090:  10 08 01 00  6B 80 10 B4  20 00 00 80  22 32 11 20 
      Offset 0A0:  EB 02 00 5D  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  67 86 85 97  F6 00 00 00  D2 16 DC 21  FA C1 85 1B 
      Offset 0C0:  00 00 01 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  D8 B4 D6 2B  91 17 07 A5  DA 32 44 25  00 00 00 00 
      Offset 0E0:  D0 91 CC 43  10 14 CC B9  10 A1 C4 61  79 94 26 29 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F03:  AMD Hammer - Miscellaneous Control
                  
      Offset 000:  22 10 03 11  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  F0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  FF 3B 04 00  40 00 50 0A  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 A0 3B 7E 
      Offset 060:  1C 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  11 01 02 51  11 80 00 50  00 2A 00 08  1A 22 00 00 
      Offset 080:  00 00 07 23  13 21 13 21  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  10 20 00 00  50 F0 A0 61  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  01 A7 0D 00  00 00 70 00  25 26 26 00 
      Offset 0E0:  00 00 00 00  3A 20 47 00  19 17 00 00  00 00 00 00 
      Offset 0F0:  0F 00 10 00  00 00 00 00  00 00 00 00  B1 0F 06 00 

    B01 D08 F00:  C-Media CMI8738/C3DX Audio Device
                  
      Offset 000:  F6 13 11 01  05 01 10 02  10 00 01 04  00 40 00 00 
      Offset 010:  01 D8 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  F6 13 11 01 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  11 01 02 18 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 00 02 06  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F00:  ATI Radeon HD 5570 (Redwood) Video Adapter
                  
      Offset 000:  02 10 D9 68  07 04 10 00  00 00 00 03  10 00 80 00 
      Offset 010:  0C 00 00 C0  00 00 00 00  04 00 FE DF  00 00 00 00 
      Offset 020:  01 E8 00 00  00 00 00 00  00 00 00 00  43 10 6C 03 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 6C 03 
      Offset 050:  01 58 03 06  00 00 00 00  10 A0 12 00  A1 8F 00 00 
      Offset 060:  10 29 09 00  01 0D 00 00  00 00 01 11  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  1F 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  01 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 00 81 00  0C 30 E0 FE  00 00 00 00  B0 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F01:  ATI Redwood/Madison - High Definition Audio Controller
                  
      Offset 000:  02 10 60 AA  06 01 10 00  00 00 03 04  10 00 80 00 
      Offset 010:  04 C0 FB DF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 60 AA 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 60 AA 
      Offset 050:  01 58 03 06  00 00 00 00  10 A0 12 00  A1 8F 00 00 
      Offset 060:  10 29 09 00  01 0D 00 00  00 00 01 11  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  1F 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    ISA-0D00:     nVIDIA CK8/CK8-04/MCP2/MCP04/MCP5x/MCP6x/MCP7x NVA
                  
      Offset 00:  00 00 00 00  3F 82 E6 E1  1B 38 E6 21  02 14 00 91 
      Offset 10:  02 1F C0 A1  02 1F C0 A1  00 00 00 00  00 00 00 08 
      Offset 20:  0A 18 C0 B1  0B 38 C0 A1  04 1B 00 80  01 10 C0 B1 
      Offset 30:  42 91 E8 00  8E 8E 40 00  02 1F C0 A1  18 32 E6 A1 
      Offset 40:  00 00 00 00  47 00 4B C9  01 02 00 00  00 00 00 00 
      Offset 50:  32 18 C0 A1  05 10 00 80  01 14 C8 B1  00 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  45 00 4B C9  01 02 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  4D 00 54 C9  01 02 00 00  00 01 00 C0 
      Offset D0:  02 10 02 91  02 0C 01 91  02 10 01 91  02 14 01 91 
      Offset E0:  02 0C 00 91  02 10 00 91  02 14 00 91  02 18 40 91 
      Offset F0:  02 1C 40 91  01 1C 40 91  00 00 00 00  00 00 00 00 

    ISA-CC00:     nVIDIA MCP55/MCP6x/MCP7x THERM
                  
      Offset 00:  08 00 00 00  AC 5A 32 00  90 18 5E 1A  2E 00 00 03 
      Offset 10:  00 04 00 C0  00 00 00 00  05 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  28 3C 28 3C  00 00 00 00 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U...%.........................IBM............... 761295520......
    C000:0040  ................07/16/10 04:05..1................@..............
    C000:0080  . .......h...................h..........113-AC60100-110.REDWOOD.
    C000:00C0  PCI_EXPRESS.DDR2...68D9.12.19.0.3.AS03                          
    C000:0100                   ..              ... ...(C) 1988-2005, ATI Techn
    C000:0140  ologies Inc. .ATOMBIOSBK-ATI VER012.019.000.003.035840.5570.BIN 
    C000:0180     .530361  .133710  .        .C02503\Config.h....$...ATOM....w.
    C000:01C0  ..........C.l...........PCIR...h................ATI ATOMBIOS.\{.
    C000:0200  .........?...SG....4c..$.....V.......LP. .^..fPfQfRfSfUfVfW.....
    C000:0240  .....j.....k....f......f.(......2.......'..'..'....A..C'.W'.Y'.a
    C000:0280  .....DP. u......e.-f.......LP........DX...=...f.......fP. .,...f
    C000:02C0  Xt.. f.......S.f_f^f]f[fZfYfX.............F.f3..F...F..R.....{EZ
    C000:0300  ..........f........f.\.f.L.;.u...f.^.f.N............>...u.......
    C000:0340  ......f....e.....@.....B.............|.?n..~.....Rr........:h...
    C000:0380  .........<h.Lh.^h...PMID..lM...............<....7.f.............
    C000:03C0  ...........fPfR.1f...f....fZfX.fPfR.1f...f....fZfX........u..:&.


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
