--------[ AIDA64 Business ]---------------------------------------------------------------------------------------------

                                                AIDA64 v4.20.2800/RU
                                        4.1.611-x64
                                      http://www.aida64.com/
                                              : /CUSTOM [ TRIAL VERSION ]
                                             -
                                             
                                   Microsoft Windows 7 Ultimate 6.1.7601.18247 (Win7 RTM)
                                                  2015-06-01
                                                 12:21


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI x64-based PC
                                     Microsoft Windows 7 Ultimate
                                       [ TRIAL VERSION ]
      Internet Explorer                                 8.0.7601.17514 (IE 8.0 - Windows 7 SP1)
      DirectX                                           DirectX 11.0
                                           -
                                         
                                              [ TRIAL VERSION ]
       /                                       2015-06-01 / 12:21

     :
                                                   QuadCore AMD FX-4100, 3616 MHz
                                          Asus M5A78L-M LX3  (1 PCI, 1 PCI-E x1, 1 PCI-E x16, 2 DDR3 DIMM, Audio, Video, Gigabit LAN)
                                    AMD 760G, AMD K15
                                         [ TRIAL VERSION ]
       BIOS                                          AMI (08/24/12)
                                      (COM1)

    :
                                            NVIDIA GeForce GT 640  (2 )
                                            NVIDIA GeForce GT 640  (2 )
                                            NVIDIA GeForce GT 640  (2 )
      3D-                                    nVIDIA GeForce GT 640
                                                 Samsung SyncMaster 177N/710N/MagicSyncMaster CX701N/CX711N  [17" LCD]  (HMELA10612)

    :
                                         nVIDIA HDMI/DP @ nVIDIA GK107 - High Definition Audio Controller
                                         Realtek ALC887 @ ATI SB700 - High Definition Audio Controller

     :
       IDE                                       PCI IDE
       IDE                                       PCI IDE
                                      Generic- Multi-Card USB Device
                                      ST500DM002-1BD142 ATA Device  (500 , 7200 RPM, SATA-III)
                                    ASUS DRW-24F1ST ATA Device  (DVD+R9:8x, DVD-R9:8x, DVD+RW:24x/8x, DVD-RW:24x/6x, DVD-RAM:5x, DVD-ROM:16x, CD:48x/24x/48x DVD+RW/DVD-RW/DVD-RAM)
                                    DTSOFT Virtual CdRom Device
                                    HODUTKJ 74LAV01E SCSI CdRom Device
      SMART-                         OK

    :
      C: (NTFS)                                         [ TRIAL VERSION ]
      D: (NTFS)                                         425637  (10310  )
                                              [ TRIAL VERSION ]

    :
                                               HID
                                                    HID- 
                                                    HID- 
                                                    HID- 

    :
        IP                                [ TRIAL VERSION ]
        MAC                               50-46-5D-B8-50-3E
                                          Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller (NDIS 6.20)  (192. [ TRIAL VERSION ])

     :
       USB1                                   ATI SB700 - OHCI USB Controller
       USB1                                   ATI SB700 - OHCI USB Controller
       USB1                                   ATI SB700 - OHCI USB Controller
       USB1                                   ATI SB700 - OHCI USB Controller
       USB1                                   ATI SB700 - OHCI USB Controller
       USB2                                   ATI SB700 - EHCI USB 2.0 Controller
       USB2                                   ATI SB700 - EHCI USB 2.0 Controller
      USB-                                    GT-S7562
      USB-                                    USB2.0 Camera
      USB-                                    USB2.0 Camera
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                       USB
      USB-                                     USB 
      USB-                                     USB 

    DMI:
      DMI  BIOS                                American Megatrends Inc.
      DMI  BIOS                                   0702
      DMI                           System manufacturer
      DMI                                        System Product Name
      DMI                                System Version
      DMI                         [ TRIAL VERSION ]
      DMI  UUID                                [ TRIAL VERSION ]
      DMI                    ASUSTeK Computer INC.
      DMI                                 M5A78L-M LX3
      DMI                           Rev X.0x
      DMI                    [ TRIAL VERSION ]
      DMI                             Chassis Manufacture
      DMI                                    Chassis Version
      DMI                             [ TRIAL VERSION ]
      DMI Asset-                                [ TRIAL VERSION ]
      DMI                                       Desktop Case


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 -
      DNS               -
      DNS              
      DNS              -
     NetBIOS                 -
      DNS               -
      DNS              
      DNS              -


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           American Megatrends Inc.
                                                  0702
                                             08/24/2012
                                                  2 
       BIOS                                8.15
                                   Floppy Disk, Hard Disk, CD-ROM, ATAPI ZIP, LS-120
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS
                                 DMI, APM, ACPI, ESCD, PnP
                                   ISA, PCI, USB
                                       

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                 http://www.aida64.com/bios-updates

  [  ]

     :
                                           System manufacturer
                                                 System Product Name
                                                  System Version
                                           [ TRIAL VERSION ]
      SKU#                                              To Be Filled By O.E.M.
                                               To Be Filled By O.E.M.
        ID                       [ TRIAL VERSION ]
                                           

  [   ]

      :
                                           ASUSTeK Computer INC.
                                                 M5A78L-M LX3
                                                  Rev X.0x
                                           [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/Motherboards
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates
       BIOS                                 http://www.aida64.com/bios-updates

  [  ]

     :
                                           Chassis Manufacture
                                                  Chassis Version
                                           [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                                
                                     
                               
                                  
                                   

  [  / AMD FX(tm)-4100 Quad-Core Processor ]

     :
                                           AMD
                                                  AMD FX(tm)-4100 Quad-Core Processor
                                           To Be Filled By O.E.M.
                                            To Be Filled By O.E.M.
                                          To Be Filled By O.E.M.
                                          200 
                                     3600 
                                          3600 
                                                     Central Processor
                                       1.4 V
                                                  
                                               Socket AM3
                                              AM3R2
      HTT / CMP                                         1 / 4
                                             64-bit

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

  [ - / L1-Cache ]

     :
                                                     
                                                1 ns
                                                  
                                             Write-Back
                                         2-way Set-Associative
                                       192 
                                      192 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L1-Cache

  [ - / L2-Cache ]

     :
                                                     
                                                1 ns
                                                  
                                             Write-Back
                                         16-way Set-Associative
                                       4096 
                                      4096 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L2-Cache

  [ - / L3-Cache ]

     :
                                                     
                                                1 ns
                                                  
                                             Write-Back
                                         64-way Set-Associative
                                       8192 
                                      8192 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L3-Cache

  [   / System Memory ]

      :
                                               
                                     
                                         
      .                                  16 
                                        2

  [   / DIMM0 ]

      :
      -                                       DIMM
                                                     Synchronous
                                                  2 
      .                                      1600 
                                             64 
                                            64 
                                              DIMM0
                                                    BANK0
                                           Manufacturer0
                                           SerNum0
                                            AssetTagNum0
                                          PartNum0

  [   / DIMM1 ]

      :
      -                                       DIMM
                                                     Synchronous
                                                  2 
      .                                      1600 
                                             64 
                                            64 
                                              DIMM1
                                                    BANK1
                                           Manufacturer1
                                           SerNum1
                                            AssetTagNum1
                                          PartNum1

  [   / PCIEX1_1 ]

      :
                                       PCIEX1_1
                                                     PCI-E
                                           
                                        32-bit
                                                   

  [   / PCIE16X ]

      :
                                       PCIE16X
                                                     PCI-E
                                           
                                        32-bit
                                                   

  [   / PCI1 ]

      :
                                       PCI1
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / Keyboard ]

      :
                                                Keyboard Port
                                   PS/2 KeyBoard
                                    
                                      
                                       PS/2

  [   / PS2Mouse ]

      :
                                                Mouse Port
                                   PS/2 Mouse
                                    
                                      PS2Mouse
                                       PS/2

  [   / USB12 ]

      :
                                                USB
                                   USB12
                                    
                                      USB12
                                       USB

  [   / USB34 ]

      :
                                                USB
                                   USB34
                                    
                                      USB34
                                       USB

  [   / LAN ]

      :
                                                Network Port
                                   LAN
                                    
                                      LAN
                                       RJ-45

  [   / Audio_Line_In ]

      :
                                                Audio Port
                                   Audio_Line_In
                                    
                                      Audio_Line_In
                                       Mini-jack (headphones)

  [   / Audio_Line_Out ]

      :
                                                Audio Port
                                   Audio_Line_Out
                                    
                                      Audio_Line_Out
                                       Mini-jack (headphones)

  [   / Audio_Mic_In ]

      :
                                                Audio Port
                                   Audio_Mic_In
                                    
                                      Audio_Mic_In
                                       Mini-jack (headphones)

  [   / D_SUB ]

      :
                                                Video Port
                                   VGA
                                    
                                      D_SUB
                                       DB-15 pin female

  [   / COM1 ]

      :
                                   COM1
                                    
                                      COM1
                                       9 Pin Dual Inline (pin 10 cut)

  [   / SATA3G_1 ]

      :
                                   SATA3G_1
                                       

  [   / SATA3G_2 ]

      :
                                   SATA3G_2
                                       

  [   / SATA3G_3 ]

      :
                                   SATA3G_3
                                       

  [   / SATA3G_4 ]

      :
                                   SATA3G_4
                                       

  [   / CPU FAN ]

      :
                                   CPU FAN
                                       

  [   / CHA FAN ]

      :
                                   CHA FAN
                                       

  [   / USB56 ]

      :
                                                USB
                                   USB56
                                    USB
                                       

  [   / USB78 ]

      :
                                                USB
                                   USB78
                                    USB
                                       

  [   / PANEL ]

      :
                                   PANEL
                                       

  [   / AAFP ]

      :
                                   AAFP
                                       

  [   / ATI ]

      :
                                                ATI
                                                     Video
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Ethernet
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Sound
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                  

  [  ]

    :
      OEM String                                        50465DB8503E
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   QuadCore AMD FX-4100
                                             Zambezi
                                              OR-B2
      Engineering Sample                                
        CPUID                                      AMD FX(tm)-4100 Quad-Core Processor
       CPUID                                      00600F12h

     :
                                               3616.4 MHz

     :
       L1                                        64  per module
       L1                                      [ TRIAL VERSION ]
       L2                                            2  per module  (On-Die, ECC, Full-Speed)
       L3                                            8   (On-Die, ECC, NB-Speed)

      :
      ID                                  65-0702-000001-00101111-082412-RS760_SB710$A2035001_BIOS DATE: 08/24/12 15:39:49 VER: 07.02
                                          Asus M5A78L-M LX3  (1 PCI, 1 PCI-E x1, 1 PCI-E x16, 2 DDR3 DIMM, Audio, Video, Gigabit LAN)

       ():
                                    AMD 760G, AMD K15

     BIOS:
       BIOS                                  08/24/12
       BIOS                            11/20/12
      DMI  BIOS                                   0702


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                         
                              
                          


--------[  ]-----------------------------------------------------------------------------------------------------

     :
                                              CPU, HDD
                                            Driver  (NV-DRV)

    :
       1 /  1                                     0 C  (32 F)
       1 /  2                                     0 C  (32 F)
       1 /  3                                     0 C  (32 F)
       1 /  4                                     0 C  (32 F)
                                    41 C  (106 F)
      ST500DM002-1BD142                                 [ TRIAL VERSION ]

    :
                                                  0.950 V


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   QuadCore AMD FX-4100, 3616 MHz
                                             Zambezi
                                              OR-B2
                                        x86, x86-64, MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, SSE4A, XOP, AVX, FMA4, AES
      Engineering Sample                                
       L1                                        64  per module
       L1                                      [ TRIAL VERSION ]
       L2                                            2  per module  (On-Die, ECC, Full-Speed)
       L3                                            8   (On-Die, ECC, NB-Speed)

       :
                                              941 Pin uPGA
                                          40 mm x 40 mm
                                       [ TRIAL VERSION ] .
                                  32 nm CMOS, Cu, HKMG, SOI, Immersion Lithography
                                         [ TRIAL VERSION ] mm2

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

    Multi CPU:
      ID                                  ASUS
      CPU #1                                            AMD FX(tm)-4100 Quad-Core Processor, 3616 
      CPU #2                                            AMD FX(tm)-4100 Quad-Core Processor, 3616 
      CPU #3                                            AMD FX(tm)-4100 Quad-Core Processor, 3616 
      CPU #4                                            AMD FX(tm)-4100 Quad-Core Processor, 3616 

     :
       1 /  1                                     0 %
       1 /  2                                     25 %
       1 /  3                                     25 %
       1 /  4                                     0 %


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               AuthenticAMD
        CPUID                                      AMD FX(tm)-4100 Quad-Core Processor
       CPUID                                      00600F12h
        CPUID                          00600F12h
                                  D0h  (Socket AM3+)
      HTT / CMP                                         0 / 4

     :
      64- x86- (AMD64, Intel64)            
      AMD 3DNow!                                         
      AMD 3DNow! Professional                            
      AMD 3DNowPrefetch                                 
      AMD Enhanced 3DNow!                                
      AMD Extended MMX                                  
      AMD FMA4                                          , 
      AMD MisAligned SSE                                
      AMD SSE4A                                         
      AMD XOP                                           , 
      Cyrix Extended MMX                                 
      Enhanced REP MOVSB/STOSB                           
      Float-16 Conversion Instructions                   
      IA-64                                              
      IA AES Extensions                                 
      IA AVX                                            , 
      IA AVX2                                            
      IA AVX-512                                         
      IA AVX-512 Conflict Detection Instructions         
      IA AVX-512 Exponential and Reciprocal Instructions 
      IA AVX-512 Prefetch Instructions                   
      IA BMI1                                            
      IA BMI2                                            
      IA FMA                                             
      IA MMX                                            
      IA SHA Extensions                                  
      IA SSE                                            
      IA SSE2                                           
      IA SSE3                                           
      IA Supplemental SSE3                              
      IA SSE4.1                                         
      IA SSE4.2                                         
      VIA Alternate Instruction Set                      
       ADCX / ADOX                             
       CLFLUSH                                
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       INVPCID                                 
       LAHF / SAHF                            
       LZCNT                                  
       MONITOR / MWAIT                        
       MONITORX / MWAITX                       
       MOVBE                                   
       PCLMULQDQ                              
       POPCNT                                 
       PREFETCHWT1                             
       RDFSBASE / RDGSBASE / WRFSBASE / WRGSBASE 
       RDRAND                                  
       RDSEED                                  
       RDTSCP                                 
       SKINIT / STGI                          
       SYSCALL / SYSRET                       
       SYSENTER / SYSEXIT                     
      Trailing Bit Manipulation Instructions             
       VIA FEMMS                               

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
         (DEP, NX, EDB)           
      Hardware Random Number Generator (RNG)             
      Hardware Random Number Generator 2 (RNG2)          
      Memory Protection Extensions (MPX)                 
      PadLock Hash Engine (PHE)                          
      PadLock Hash Engine 2 (PHE2)                       
      PadLock Montgomery Multiplier (PMM)                
      PadLock Montgomery Multiplier 2 (PMM2)             
         (PSN)                    
      Safer Mode Extensions (SMX)                        
      Software Guard Extensions (SGX)                    
      Supervisor Mode Access Prevention (SMAP)           
      Supervisor Mode Execution Protection (SMEP)        

     :
      Application Power Management (APM)                , 
      Automatic Clock Control                            
      Core C6 State (CC6)                               , 
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                         
      Enhanced SpeedStep Technology (EIST, ESS)          
      Frequency ID Control                               
      Hardware P-State Control                          
      Hardware Thermal Control (HTC)                     
      LongRun                                            
      LongRun Table Interface                            
      Overstress                                         
      Package C6 State (PC6)                             
      Parallax                                           
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                       
      Software Thermal Control                           
                                               
      Thermal Monitor 1                                  
      Thermal Monitor 2                                  
      Thermal Monitor 3                                  
      Thermal Monitoring                                
      Thermal Trip                                      
      Voltage ID Control                                 

     :
      Extended Page Table (EPT)                          
      Hypervisor                                        
       INVEPT                                  
       INVVPID                                 
      Nested Paging (NPT, RVI)                          
      Secure Virtual Machine (SVM, Pacifica)            
      Virtual Machine Extensions (VMX, Vanderpool)       
      Virtual Processor ID (VPID)                        

     CPUID:
      1 GB Page Size                                    
      36-bit Page Size Extension                        
      64-bit DS Area                                     
      Adaptive Overclocking                              
      Address Region Registers (ARR)                     
      Configurable TDP (cTDP)                            
      Core Performance Boost (CPB)                      
      Core Performance Counters                         
      CPL Qualified Debug Store                          
      Data Breakpoint Extension                          
      Debug Trace Store                                  
      Debugging Extension                               
      Deprecated FPU CS and FPU DS                       
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Dynamic Configurable TDP (DcTDP)                   
      Extended APIC Register Space                      
      Fast Save & Restore                               
      Hardware Lock Elision (HLE)                        
      Hybrid Boost                                       
      Hyper-Threading Technology (HTT)                   
      Instruction Based Sampling                        
      Invariant Time Stamp Counter                      
      L1 Context ID                                      
      L2I Performance Counters                           
      Lightweight Profiling                             
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      NB Performance Counters                           
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event (PBE)                          
      Performance Time Stamp Counter (PTSC)              
      Physical Address Extension (PAE)                  
      Process Context Identifiers (PCID)                 
      Processor Feedback Interface                       
      Processor Trace (PT)                               
      Quality of Service Monitoring (QM)                 
      Restricted Transactional Memory (RTM)              
      Self-Snoop                                         
      Time Stamp Counter (TSC)                          
      Turbo Boost                                        
      Virtual Mode Extension                            
      Watchdog Timer                                    
      x2APIC                                             
      XGETBV / XSETBV OS Enabled                        
      XSAVE / XRSTOR / XSETBV / XGETBV Extended States  
      XSAVEOPT                                           

    CPUID Registers (CPU #1):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65
      CPUID 00000001                                    00600F12-00040800-1E98220B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 00000006                                    00000000-00000000-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-000003C0-40000000
      CPUID 0000000D                                    00000100-00000240-00000000-00000000
      CPUID 80000000                                    8000001E-68747541-444D4163-69746E65
      CPUID 80000001                                    00600F12-10000000-01C9BFFF-2FD3FBFF
      CPUID 80000002                                    20444D41-74285846-342D296D-20303031
      CPUID 80000003                                    64617551-726F432D-72502065-7365636F
      CPUID 80000004                                    20726F73-20202020-20202020-00202020
      CPUID 80000005                                    FF20FF18-FF20FF30-10040140-40020140
      CPUID 80000006                                    64000000-64004200-08008140-0040C140
      CPUID 80000007                                    00000000-00000000-00000000-000003D9
      CPUID 80000008                                    00003030-00000000-00004003-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00010000-00000000-000014FF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F020F018-64000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000000FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-80032013-00010200-8000000F
      CPUID 8000001D                                    00000121-00C0003F-0000003F-00000000
      CPUID 8000001D                                    00004122-0040003F-000001FF-00000000
      CPUID 8000001D                                    00004143-03C0003F-000007FF-00000001
      CPUID 8000001D                                    0000C163-0FC0003F-000007FF-00000001
      CPUID 8000001E                                    00000010-00000100-00000000-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65
      CPUID 00000001                                    00600F12-01040800-1E98220B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 00000006                                    00000000-00000000-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-000003C0-40000000
      CPUID 0000000D                                    00000100-00000240-00000000-00000000
      CPUID 80000000                                    8000001E-68747541-444D4163-69746E65
      CPUID 80000001                                    00600F12-10000000-01C9BFFF-2FD3FBFF
      CPUID 80000002                                    20444D41-74285846-342D296D-20303031
      CPUID 80000003                                    64617551-726F432D-72502065-7365636F
      CPUID 80000004                                    20726F73-20202020-20202020-00202020
      CPUID 80000005                                    FF20FF18-FF20FF30-10040140-40020140
      CPUID 80000006                                    64000000-64004200-08008140-0040C140
      CPUID 80000007                                    00000000-00000000-00000000-000003D9
      CPUID 80000008                                    00003030-00000000-00004003-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00010000-00000000-000014FF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F020F018-64000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000000FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-80032013-00010200-8000000F
      CPUID 8000001D                                    00000121-00C0003F-0000003F-00000000
      CPUID 8000001D                                    00004122-0040003F-000001FF-00000000
      CPUID 8000001D                                    00004143-03C0003F-000007FF-00000001
      CPUID 8000001D                                    0000C163-0FC0003F-000007FF-00000001
      CPUID 8000001E                                    00000011-00000100-00000000-00000000

    CPUID Registers (CPU #3):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65
      CPUID 00000001                                    00600F12-02040800-1E98220B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 00000006                                    00000000-00000000-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-000003C0-40000000
      CPUID 0000000D                                    00000100-00000240-00000000-00000000
      CPUID 80000000                                    8000001E-68747541-444D4163-69746E65
      CPUID 80000001                                    00600F12-10000000-01C9BFFF-2FD3FBFF
      CPUID 80000002                                    20444D41-74285846-342D296D-20303031
      CPUID 80000003                                    64617551-726F432D-72502065-7365636F
      CPUID 80000004                                    20726F73-20202020-20202020-00202020
      CPUID 80000005                                    FF20FF18-FF20FF30-10040140-40020140
      CPUID 80000006                                    64000000-64004200-08008140-0040C140
      CPUID 80000007                                    00000000-00000000-00000000-000003D9
      CPUID 80000008                                    00003030-00000000-00004003-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00010000-00000000-000014FF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F020F018-64000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000000FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-80032013-00010200-8000000F
      CPUID 8000001D                                    00000121-00C0003F-0000003F-00000000
      CPUID 8000001D                                    00004122-0040003F-000001FF-00000000
      CPUID 8000001D                                    00004143-03C0003F-000007FF-00000001
      CPUID 8000001D                                    0000C163-0FC0003F-000007FF-00000001
      CPUID 8000001E                                    00000012-00000101-00000000-00000000

    CPUID Registers (CPU #4):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65
      CPUID 00000001                                    00600F12-03040800-1E98220B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 00000006                                    00000000-00000000-00000001-00000000
      CPUID 00000007                                    00000000-00000000-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-000003C0-40000000
      CPUID 0000000D                                    00000100-00000240-00000000-00000000
      CPUID 80000000                                    8000001E-68747541-444D4163-69746E65
      CPUID 80000001                                    00600F12-10000000-01C9BFFF-2FD3FBFF
      CPUID 80000002                                    20444D41-74285846-342D296D-20303031
      CPUID 80000003                                    64617551-726F432D-72502065-7365636F
      CPUID 80000004                                    20726F73-20202020-20202020-00202020
      CPUID 80000005                                    FF20FF18-FF20FF30-10040140-40020140
      CPUID 80000006                                    64000000-64004200-08008140-0040C140
      CPUID 80000007                                    00000000-00000000-00000000-000003D9
      CPUID 80000008                                    00003030-00000000-00004003-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00010000-00000000-000014FF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F020F018-64000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000000FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-80032013-00010200-8000000F
      CPUID 8000001D                                    00000121-00C0003F-0000003F-00000000
      CPUID 8000001D                                    00004122-0040003F-000001FF-00000000
      CPUID 8000001D                                    00004143-03C0003F-000007FF-00000001
      CPUID 8000001D                                    0000C163-0FC0003F-000007FF-00000001
      CPUID 8000001E                                    00000013-00000101-00000000-00000000

    MSR Registers:
      CPB PStates                                       0
      CPU Clock (Normal)                                3616 MHz
      CPU Clock (TSC)                                   3616 MHz
      CPU Multiplier                                    0.0x
      MSR 0000001B                                      < FAILED >
      MSR 0000008B                                      < FAILED >
      MSR 000000E7                                      < FAILED >
      MSR 000000E8                                      < FAILED >
      MSR C0010004                                      < FAILED >
      MSR C0010005                                      < FAILED >
      MSR C0010006                                      < FAILED >
      MSR C0010007                                      < FAILED >
      MSR C0010015                                      < FAILED >
      MSR C001001F                                      < FAILED >
      MSR C0010055                                      < FAILED >
      MSR C0010058                                      < FAILED >
      MSR C0010061                                      < FAILED >
      MSR C0010062                                      < FAILED >
      MSR C0010063                                      < FAILED >
      MSR C0010064                                      < FAILED >
      MSR C0010065                                      < FAILED >
      MSR C0010066                                      < FAILED >
      MSR C0010067                                      < FAILED >
      MSR C0010068                                      < FAILED >
      MSR C0010069                                      < FAILED >
      MSR C001006A                                      < FAILED >
      MSR C001006B                                      < FAILED >
      MSR C0010070                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010140                                      < FAILED >
      MSR C0010141                                      < FAILED >
      MSR C0011023                                      < FAILED >


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  65-0702-000001-00101111-082412-RS760_SB710$A2035001_BIOS DATE: 08/24/12 15:39:49 VER: 07.02
                                          Asus M5A78L-M LX3

        :
                                         1 Socket AM3+
                                       [ TRIAL VERSION ]
                                              2 DDR3 DIMM
                                    Audio, Video, Gigabit LAN
      -                                       Micro ATX
                                   190 mm x 240 mm
                                    AMD760G
                                   [ TRIAL VERSION ]

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/Motherboards
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates
       BIOS                                 http://www.aida64.com/bios-updates


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   [ TRIAL VERSION ]
                                                  [ TRIAL VERSION ]
                                                1345 
                                                [ TRIAL VERSION ]

       :
                                                   8154 
                                                  3278 
                                                4877 
                                                40 %

     :
                                                   12233 
                                                  6011 
                                                6222 
                                                49 %

     :
                                            C:\pagefile.sys
                                           4078 
      /                           49  / 49 
                                                1 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[  ]------------------------------------------------------------------------------------------------------

  [  : AMD RS780L ]

      :
                                            AMD RS780L
                                                  01

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [  : AMD K15 IMC ]

      :
                                            AMD K15 IMC
                                                  00
      Probe Filter                                      , 

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [  : [ TRIAL VERSION ] ]

      :
                                               [ TRIAL VERSION ]
                                                  00

    High Definition Audio:
                                               Realtek ALC887
      ID                                          10EC0887h / 10438445h
                                            1003h
                                               Audio

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          AMI
       BIOS                                       0702
       BIOS                                  08/24/12
       BIOS                            11/20/12

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                 http://www.aida64.com/bios-updates


--------[  ]----------------------------------------------------------------------------------------------------

    aida64.exe               C:\Program Files (x86)\AIDA64\Extreme\aida64.exe                              32          5468             32 
    aida64.exe               C:\ProgramData\aida64business\aida64.exe                                      32         50472             42 
    audiodg.exe                                                                                            64         21244             21 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64          4328              2 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64          8856              2 
    DTShellHlp.exe           C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe                              32         19240              3 
    dwm.exe                  C:\Windows\system32\Dwm.exe                                                   64         31684             37 
    egui.exe                 C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe                           64         11864              3 
    ekrn.exe                 C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe                       32           103            100 
    explorer.exe             C:\Windows\Explorer.EXE                                                       64         76176             57 
    firefox.exe              C:\Program Files (x86)\Mozilla Firefox\firefox.exe                            32           478            444 
    jusched.exe              C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe              32          4944              1 
    lsass.exe                C:\Windows\system32\lsass.exe                                                 64         12316              4 
    lsm.exe                  C:\Windows\system32\lsm.exe                                                   64          4496              2 
    notepad.exe              C:\Windows\system32\NOTEPAD.EXE                                               64          6708              1 
    nvvsvc.exe               C:\Windows\system32\nvvsvc.exe                                                64         13408              5 
    nvvsvc.exe               C:\Windows\system32\nvvsvc.exe                                                64          7780              2 
    nvxdsync.exe             C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe                      64         21844              9 
    PnkBstrA.exe             C:\Windows\SysWOW64\PnkBstrA.exe                                              32          4312              1 
    ProfitTaskMonitor.exe    C:\Program Files (x86)\ProfitTask\ProfitTaskMonitor.exe                       32         36460             23 
    services.exe             C:\Windows\system32\services.exe                                              64         10196              6 
    sidebar.exe              C:\Program Files\Windows Sidebar\sidebar.exe                                  64         20616              7 
    smss.exe                                                                                               64          1164              0 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64           134            126 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         16856             15 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         17748             14 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         27480             35 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          8156              3 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         31520             17 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64          2956              1 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          5980              2 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         64512              7 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         12864              6 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         15364              8 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         10452              4 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          8008              3 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         22712             24 
    System Idle Process                                                                                                     24              0 
    System                                                                                                 64           300              0 
    taskeng.exe              C:\Windows\system32\taskeng.exe                                               64          6252              2 
    taskhost.exe             C:\Windows\system32\taskhost.exe                                              64         10052              8 
    TechReport.exe           D:\\TechReport_1.4\TechReport.exe                                        32         55896             52 
    TuneUpUtilitiesApp64.exe  C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe         64         10308              2 
    TuneUpUtilitiesService64.exe  C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe     64         19048              9 
    ufdsvc.exe               C:\Windows\SysWOW64\ufdsvc.exe                                                32          3212              1 
    wininit.exe              C:\Windows\system32\wininit.exe                                               64          4728              1 
    winlogon.exe             C:\Windows\system32\winlogon.exe                                              64          7576              3 
    WmiPrvSE.exe             C:\Windows\system32\wbem\wmiprvse.exe                                         32         10120              4 
    wmpnetwk.exe             C:\Program Files\Windows Media Player\wmpnetwk.exe                            64         10520             10 
    WorldOfTanks.exe         D:\World_of_Tanks\worldoftanks.exe                                            32           752            917 
    WUDFHost.exe             C:\Windows\System32\WUDFHost.exe                                              64          6136              2 
    WUDFHost.exe             C:\Windows\System32\WUDFHost.exe                                              32          6836              2 


--------[   ]------------------------------------------------------------------------------------------

    1394ohci         1394 OHCI- -                                   1394ohci.sys          6.1.7601.17514                        
    ACPI              Microsoft ACPI                                                  ACPI.sys              6.1.7601.17514                        
    AcpiPmi              ACPI                              acpipmi.sys           6.1.7601.17514                        
    adp94xx          adp94xx                                                                 adp94xx.sys           1.6.6.4                               
    adpahci          adpahci                                                                 adpahci.sys           1.6.6.1                               
    adpu320          adpu320                                                                 adpu320.sys           7.2.0.0                               
    AFD              Ancillary Function Driver for Winsock                                   afd.sys               6.1.7601.18264                        
    agp440           Intel -   AGP                                                 agp440.sys            6.1.7600.16385                        
    AIDA64Driver     FinalWire AIDA64 Kernel Driver                                          kerneld.x64                                                 
    aliide           aliide                                                                  aliide.sys            1.2.0.0                               
    amdide           amdide                                                                  amdide.sys            6.1.7600.16385                        
    AmdK8            AMD K8 Processor Driver                                                 amdk8.sys             6.1.7600.16385                        
    AmdPPM             AMD                                                  amdppm.sys            6.1.7600.16385                        
    amdsata          amdsata                                                                 amdsata.sys           1.1.2.5                               
    amdsbs           amdsbs                                                                  amdsbs.sys            3.6.1540.127                          
    amdxata          amdxata                                                                 amdxata.sys           1.1.2.5                               
    anvsnddrv        AnvSoft Virtual Sound Device                                            anvsnddrv.sys         1.2.0.0                               
    AppID             AppID                                                           appid.sys             6.1.7601.17514                        
    arc              arc                                                                     arc.sys               5.2.0.10384                           
    arcsas           arcsas                                                                  arcsas.sys            5.2.0.16119                           
    AsIO             AsIO                                                                    AsIO.sys                                                    
    AsUpIO           AsUpIO                                                                  AsUpIO.sys                                                  
    AsyncMac            RAS                                       asyncmac.sys          6.1.7600.16385                        
    atapi             IDE                                                               atapi.sys             6.1.7600.16385                        
    AtiPcie          AMD PCI Express (3GIO) Filter                                           AtiPcie.sys           1.3.2.54                              
    b06bdrv          Broadcom NetXtreme II VBD                                               bxvbda.sys            4.8.2.0                               
    b57nd60a         Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0                          b57nd60a.sys          10.100.4.0                            
    Beep             Beep                                                                                                                                
    blbdrive         blbdrive                                                                blbdrive.sys          6.1.7600.16385                        
    bowser                                                           bowser.sys            6.1.7601.17565             
    BrFiltLo         Brother USB Mass-Storage Lower Filter Driver                            BrFiltLo.sys          1.10.0.2                              
    BrFiltUp         Brother USB Mass-Storage Upper Filter Driver                            BrFiltUp.sys          1.4.0.1                               
    Brserid          Brother MFC Serial Port Interface Driver (WDM)                          Brserid.sys           1.0.1.6                               
    BrSerWdm         Brother WDM Serial driver                                               BrSerWdm.sys          1.0.0.20                              
    BrUsbMdm         Brother MFC USB Fax Only Modem                                          BrUsbMdm.sys          1.0.0.12                              
    BrUsbSer         Brother MFC USB Serial WDM Driver                                       BrUsbSer.sys          1.0.1.3                               
    BTHMODEM         Bluetooth Serial Communications Driver                                  bthmodem.sys          6.1.7600.16385                        
    cdfs             CD/DVD File System Reader                                               cdfs.sys              6.1.7600.16385             
    cdrom             CD-ROM                                                 cdrom.sys             6.1.7601.17514                        
    circlass         Consumer IR Devices                                                     circlass.sys          6.1.7600.16385                        
    CLFS               (CLFS)                                                     CLFS.sys              6.1.7600.16385                        
    clwvd            CyberLink WebCam Virtual Driver                                         clwvd.sys             1.0.0.4403                            
    CmBatt           Microsoft ACPI Control Method Battery Driver                            CmBatt.sys            6.1.7600.16385                        
    cmdide           cmdide                                                                  cmdide.sys            2.0.7.0                               
    CNG              CNG                                                                     cng.sys               6.1.7601.17856                        
    Compbatt         Compbatt                                                                compbatt.sys          6.1.7600.16385                        
    CompositeBus                                          CompositeBus.sys      6.1.7601.17514                        
    crcdisk          Crcdisk Filter Driver                                                   crcdisk.sys           6.1.7600.16385                        
    CSC                                                               csc.sys               6.1.7601.17514                        
    DfsC             DFS Namespace Client Driver                                             dfsc.sys              6.1.7601.17514             
    discache         System Attribute Cache                                                  discache.sys          6.1.7600.16385                        
    Disk                                                                         disk.sys              6.1.7600.16385                        
    drmkaud                                                 drmkaud.sys           6.1.7600.16385                        
    DrvAgent64       DrvAgent64                                                              DrvAgent64.SYS        1.0.0.1                               
    dtsoftbus01      DAEMON Tools Virtual Bus Driver                                         dtsoftbus01.sys       4.41.315.256                          
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           6.1.7601.18228                        
    eamonm           eamonm                                                                  eamonm.sys            4.2.65.0                   
    ebdrv            Broadcom NetXtreme II 10 GigE VBD                                       evbda.sys             4.8.13.0                              
    ehdrv            ehdrv                                                                   ehdrv.sys             4.2.62.0                              
    elxstor          elxstor                                                                 elxstor.sys           7.2.10.211                            
    epfwwfpr         epfwwfpr                                                                epfwwfpr.sys          4.2.62.0                              
    ErrDev               (Microsoft)                        errdev.sys            6.1.7600.16385                        
    exfat            exFAT File System Driver                                                                                                 
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc              Floppy Disk Controller Driver                                           fdc.sys               6.1.7600.16385                        
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          6.1.7600.16385             
    Filetrace        Filetrace                                                               filetrace.sys         6.1.7600.16385             
    flpydisk         Floppy Disk Driver                                                      flpydisk.sys          6.1.7600.16385                        
    FltMgr                                                                  fltmgr.sys            6.1.7601.17514             
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         6.1.7600.16385             
    fvevol               Bitlocker                              fvevol.sys            6.1.7601.18062                        
    gagp30kx         Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms             gagp30kx.sys          6.1.7600.16385                        
    hcw85cir         Hauppauge Consumer Infrared Receiver                                    hcw85cir.sys          1.31.27127.0                          
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           6.1.7601.17514                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          6.1.7601.17514                        
    HidBatt          HID UPS Battery Driver                                                  HidBatt.sys           6.1.7600.16385                        
    HidBth           Microsoft Bluetooth HID Miniport                                        hidbth.sys            6.1.7600.16385                        
    HidIr            Microsoft Infrared HID Driver                                           hidir.sys             6.1.7600.16385                        
    HidUsb             HID Microsoft                                            hidusb.sys            6.1.7601.17514                        
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            6.12.6.64                             
    HTTP             HTTP                                                                    HTTP.sys              6.1.7601.17514                        
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          6.1.7601.17514                        
    i8042prt          i8042-     PS/2                          i8042prt.sys          6.1.7600.16385                        
    iaStorV          RAID- Intel  Windows 7                                     iaStorV.sys           8.6.2.1014                            
    iirsp            iirsp                                                                   iirsp.sys             5.4.22.0                              
    IntcAzAudAddService  Service for Realtek HD Audio (WDM)                                      RTKVHD64.sys          6.0.1.6873                            
    intelide         intelide                                                                intelide.sys          6.1.7600.16385                        
    intelppm         Intel Processor Driver                                                  intelppm.sys          6.1.7600.16385                        
    IpFilterDriver     IP-                                              ipfltdrv.sys          6.1.7601.17514                        
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           6.1.7601.17514                        
    IPNAT            IP Network Address Translator                                           ipnat.sys             6.1.7600.16385                        
    IRENUM           IR Bus Enumerator                                                       irenum.sys            6.1.7600.16385                        
    isapnp           isapnp                                                                  isapnp.sys            6.1.7600.16385                        
    iScsiPrt          iScsiPort                                                       msiscsi.sys           6.1.7601.17514                        
    kbdclass                                                          kbdclass.sys          6.1.7600.16385                        
    kbdhid             HID                                                  kbdhid.sys            6.1.7601.17514                        
    KSecDD           KSecDD                                                                  ksecdd.sys            6.1.7601.17856                        
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           6.1.7601.17856                        
    ksthunk          Kernel Streaming Thunks                                                 ksthunk.sys           6.1.7600.16385                        
    L1C              NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller       L1C62x64.sys          2.0.11.12                             
    lltdio           Link-Layer Topology Discovery Mapper I/O Driver                         lltdio.sys            6.1.7600.16385                        
    LSI_FC           LSI_FC                                                                  lsi_fc.sys            1.28.3.52                             
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.28.3.52                             
    LSI_SAS2         LSI_SAS2                                                                lsi_sas2.sys          2.0.2.71                              
    LSI_SCSI         LSI_SCSI                                                                lsi_scsi.sys          1.28.3.67                             
    luafv                                            luafv.sys             6.1.7600.16385             
    megasas          megasas                                                                 megasas.sys           4.5.1.64                              
    MegaSR           MegaSR                                                                  MegaSR.sys            13.5.409.2009                         
    Modem            Modem                                                                   modem.sys             6.1.7600.16385                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           6.1.7600.16385                        
    mouclass                                                                mouclass.sys          6.1.7600.16385                        
    mouhid             HID                                                        mouhid.sys            6.1.7600.16385                        
    mountmgr                                                        mountmgr.sys          6.1.7601.17514                        
    mpio             Microsoft Multi-Path Bus                                         mpio.sys              6.1.7601.17514                        
    mpsdrv              Windows                                 mpsdrv.sys            6.1.7600.16385                        
    MRxDAV              WebDav                                 mrxdav.sys            6.1.7601.18201             
    mrxsmb              - SMB                              mrxsmb.sys            6.1.7601.17605             
    mrxsmb10         - SMB 1.x                                            mrxsmb10.sys          6.1.7601.17647             
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          6.1.7601.17605             
    msahci           msahci                                                                  msahci.sys            6.1.7601.17514                        
    msdsm            Microsoft Multi-Path                      msdsm.sys             6.1.7601.17514                        
    Msfs             Msfs                                                                                                                     
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         6.1.7600.16385                        
    msisadrv         msisadrv                                                                msisadrv.sys          6.1.7600.16385                        
    MSKSSRV             Microsoft                                   MSKSSRV.sys           6.1.7600.16385                        
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          6.1.7600.16385                        
    MSPQM                Microsoft                     MSPQM.sys             6.1.7600.16385                        
    MsRPC            MsRPC                                                                                                                               
    mssmbios         Microsoft System Management BIOS                                 mssmbios.sys          6.1.7600.16385                        
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             6.1.7600.16385                        
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          6.1.7600.16385                        
    MTsensor         ATK0110 ACPI UTILITY                                                    ASACPI.sys            1043.6.0.0                            
    Mup              Mup                                                                     mup.sys               6.1.7600.16385             
    NativeWifiP      NativeWiFi Filter                                                       nwifi.sys             6.1.7600.16385                        
    NDIS               NDIS                                                  ndis.sys              6.1.7601.17939                        
    NdisCap          NDIS Capture LightWeight Filter                                         ndiscap.sys           6.1.7600.16385                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          6.1.7600.16385                        
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           6.1.7601.17514                        
    NdisWan          NDIS- WAN                                       ndiswan.sys           6.1.7601.17514                        
    NDProxy          NDIS Proxy                                                                                                                          
    NetBIOS          NetBIOS Interface                                                       netbios.sys           6.1.7600.16385             
    NetBT            NetBT                                                                   netbt.sys             6.1.7601.17514                        
    netr28ux         RT2870 USB Extensible Wireless LAN Card Driver                          netr28ux.sys          3.2.9.0                               
    nfrd960          nfrd960                                                                 nfrd960.sys           7.10.0.0                              
    NPF              WinPcap Packet Driver (NPF)                                             NPF.sys               4.1.0.2001                            
    Npfs             Npfs                                                                                                                     
    nsiproxy         NSI proxy service driver.                                               nsiproxy.sys          6.1.7600.16385                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nv_agp           NVIDIA nForce   AGP                                           nv_agp.sys            6.1.7600.16385                        
    NVHDA            Service for NVIDIA High Definition Audio Driver                         nvhda64v.sys          1.3.34.3                              
    nvlddmkm         nvlddmkm                                                                nvlddmkm.sys          9.18.13.5286                          
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.18                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.18                             
    nvvad_WaveExtensible  NVIDIA Virtual Audio Device (Wave Extensible) (WDM)                     nvvad64v.sys                                                
    ohci1394         1394 OHCI- - ( )               ohci1394.sys          6.1.7600.16385                        
    Parport          Parallel port driver                                                    parport.sys           6.1.7600.16385                        
    partmgr                                                                 partmgr.sys           6.1.7601.17796                        
    pci               PCI                                                         pci.sys               6.1.7601.17514                        
    pciide           pciide                                                                  pciide.sys            6.1.7600.16385                        
    pcmcia           pcmcia                                                                  pcmcia.sys            6.1.7600.16385                        
    pcw              Performance Counters for Windows Driver                                 pcw.sys               6.1.7600.16385                        
    PEAUTH           PEAUTH                                                                  peauth.sys            6.1.7600.16385                        
    PptpMiniport     - WAN (PPTP)                                                    raspptp.sys           6.1.7601.17514                        
    Processor        Processor Driver                                                        processr.sys          6.1.7600.16385                        
    Psched             QoS                                                 pacer.sys             6.1.7601.17514                        
    ql2300           ql2300                                                                  ql2300.sys            9.1.8.6                               
    ql40xx           ql40xx                                                                  ql40xx.sys            2.1.3.20                              
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          6.1.7600.16385                        
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            6.1.7600.16385                        
    RasAgileVpn      WAN Miniport (IKEv2)                                                    AgileVpn.sys          6.1.7600.16385                        
    Rasl2tp          - WAN (L2TP)                                                    rasl2tp.sys           6.1.7601.17514                        
    RasPppoe          PPPOE                                          raspppoe.sys          6.1.7600.16385                        
    RasSstp          - WAN (SSTP)                                                    rassstp.sys           6.1.7600.16385                        
    rdbss                                               rdbss.sys             6.1.7601.17514             
    rdpbus           Remote Desktop Device Redirector Bus Driver                             rdpbus.sys            6.1.7600.16385                        
    RDPCDD           RDPCDD                                                                  RDPCDD.sys            6.1.7600.16385                        
    RDPDR            Terminal Server Device Redirector Driver                                rdpdr.sys             6.1.7601.17514                        
    RDPENCDD         RDP Encoder Mirror Driver                                               rdpencdd.sys          6.1.7600.16385                        
    RDPREFMP         Reflector Display Driver used to gain access to graphics data           rdprefmp.sys          6.1.7600.16385                        
    RdpVideoMiniport  Remote Desktop Video Miniport Driver                                    rdpvideominiport.sys  6.1.7601.17514                        
    RDPWD            RDP Winstation Driver                                                                                                               
    rdyboost         ReadyBoost                                                              rdyboost.sys          6.1.7601.17514                        
    RMCAST              (RMP)                                   RMCAST.sys            6.1.7601.17514                        
    rspndr           Link-Layer Topology Discovery Responder                                 rspndr.sys            6.1.7600.16385                        
    s3cap            s3cap                                                                   vms3cap.sys           6.1.7601.17514                        
    sbp2port         SBP-2   /                                   sbp2port.sys          6.1.7601.17514                        
    scfilter           -  PnP                                  scfilter.sys          6.1.7601.17514                        
    secdrv           Security Driver                                                                                                                     
    Serenum            Serenum                                                 serenum.sys           6.1.7600.16385                        
    Serial                                                      serial.sys            6.1.7600.16385                        
    sermouse         Serial Mouse Driver                                                     sermouse.sys          6.1.7600.16385                        
    sffdisk            SFF Storage                                              sffdisk.sys           6.1.7600.16385                        
    sffp_mmc            SFF  MMC                                  sffp_mmc.sys          6.1.7600.16385                        
    sffp_sd            SFF Storage  SDBus                                 sffp_sd.sys           6.1.7601.17514                        
    sfloppy          High-Capacity Floppy Disk Drive                                         sfloppy.sys           6.1.7600.16385                        
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    Smb                TCP/IP  TCP/IPv6 ( SMB)                        smb.sys               6.1.7600.16385                        
    spldr            Security Processor Loader Driver                                                                                                    
    sptd             sptd                                                                    sptd.sys              1.81.0.0                              
    srv                Server SMB 1.xxx                                        srv.sys               6.1.7601.17608             
    srv2               Server SMB 2.xxx                                        srv2.sys              6.1.7601.17608             
    srvnet           srvnet                                                                  srvnet.sys            6.1.7601.17608             
    stexstor         stexstor                                                                stexstor.sys          5.0.1.1                               
    storflt                                   vmstorfl.sys          6.1.7601.17514                        
    storvsc          storvsc                                                                 storvsc.sys           6.1.7601.17514                        
    swenum                                                             swenum.sys            6.1.7600.16385                        
    Synth3dVsc       Synth3dVsc                                                              synth3dvsc.sys                                              
    Tcpip              TCP/IP                                                tcpip.sys             6.1.7601.18254                        
    TCPIP6           Microsoft IPv6 Protocol Driver                                          tcpip.sys             6.1.7601.18254                        
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          6.1.7601.17964                        
    TDPIPE           TDPIPE                                                                  tdpipe.sys            6.1.7600.16385                        
    TDTCP            TDTCP                                                                   tdtcp.sys             6.1.7601.17779                        
    tdx                NetIO Legacy TDI                                      tdx.sys               6.1.7601.17514                        
    TermDD                                                         termdd.sys            6.1.7601.17514                        
    TFsExDisk        TFsExDisk                                                               TFsExDisk.sys         1.0.0.1                    
    tssecsrv         Remote Desktop Services Security Filter Driver                          tssecsrv.sys          6.1.7601.18186                        
    TsUsbFlt         TsUsbFlt                                                                tsusbflt.sys          6.1.7601.17514                        
    tsusbhub         tsusbhub                                                                tsusbhub.sys                                                
    TuneUpUtilitiesDrv  TuneUpUtilitiesDrv                                                      TuneUpUtilitiesDriver64.sys  1.0.0.0                               
    tunnel                Microsoft                        tunnel.sys            6.1.7601.17514                        
    uagp35           Microsoft AGPv3.5 Filter                                                uagp35.sys            6.1.7600.16385                        
    udfs             udfs                                                                    udfs.sys              6.1.7601.17514             
    uliagpkx         Uli-   AGP                                                    uliagpkx.sys          6.1.7600.16385                        
    umbus            UMBus                                               umbus.sys             6.1.7601.17514                        
    UmPass            UMPass Microsoft                                                umpass.sys            6.1.7600.16385                        
    usbaudio           USB (WDM)                                                 usbaudio.sys          6.1.7601.18208                        
    usbccgp              USB (Microsoft)         usbccgp.sys           6.1.7601.17586                        
    usbcir           eHome   (USBCIR)                                     usbcir.sys            6.1.7601.18208                        
    usbehci            Microsoft USB 2.0  -       usbehci.sys           6.1.7601.17586                        
    usbhub             USB- ()                      usbhub.sys            6.1.7601.17586                        
    usbohci            Microsoft USB  -              usbohci.sys           6.1.7601.17586                        
    usbprint           Microsoft USB                                           usbprint.sys          6.1.7600.16385                        
    USBSTOR              USB                                  USBSTOR.SYS           6.1.7601.17577                        
    usbuhci            Microsoft USB  -         usbuhci.sys           6.1.7601.17586                        
    usbvideo         USB- (WDM)                                               usbvideo.sys          6.1.7601.18208                        
    vdrvroot             ()                   vdrvroot.sys          6.1.7600.16385                        
    vga              vga                                                                     vgapnp.sys            6.1.7600.16385                        
    VgaSave          VgaSave                                                                 vga.sys               6.1.7600.16385                        
    VGPU             VGPU                                                                    rdvgkmd.sys                                                 
    vhdmp            vhdmp                                                                   vhdmp.sys             6.1.7601.17514                        
    viaide           viaide                                                                  viaide.sys            6.0.6000.170                          
    vmbus             VMBus                                                              vmbus.sys             6.1.7601.17514                        
    VMBusHID         VMBusHID                                                                VMBusHID.sys          6.1.7601.17514                        
    volmgr                                                             volmgr.sys            6.1.7601.17514                        
    volmgrx                                                        volmgrx.sys           6.1.7601.17514                        
    volsnap                                                         volsnap.sys           6.1.7601.17514                        
    vsmraid          vsmraid                                                                 vsmraid.sys           6.0.6000.6210                         
    vwifibus           Virtual WiFi                                               vwifibus.sys          6.1.7600.16385                        
    vwififlt         Virtual WiFi Filter Driver                                              vwififlt.sys          6.1.7600.16385                        
    vwifimp          Microsoft Virtual WiFi Miniport Service                                 vwifimp.sys           6.1.7600.16385                        
    WacomPen         Wacom Serial Pen HID Driver                                             wacompen.sys          6.1.7600.16385                        
    WANARP              IP ARP                                       wanarp.sys            6.1.7601.17514                        
    Wanarpv6            IPv6 ARP                                     wanarp.sys            6.1.7601.17514                        
    Wd               Wd                                                                      wd.sys                6.1.7600.16385                        
    Wdf01000                                                 Wdf01000.sys          1.11.9200.16648                       
    WfpLwf           WFP Lightweight Filter                                                  wfplwf.sys            6.1.7600.16385                        
    WIMMount         WIMMount                                                                wimmount.sys          6.1.7600.16385             
    WinUsb           WinUsb                                                                  WinUsb.sys            6.1.7601.17514                        
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           6.1.7600.16385                        
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           6.1.7600.16385                        
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            6.2.9200.16384                        
    WUDFRd           WUDFRd                                                                  WUDFRd.sys            6.2.9200.16384                        


--------[  ]------------------------------------------------------------------------------------------------------

    AdobeARMservice                    Adobe Acrobat Update Service                                            armsvc.exe            1.7.4.0                        LocalSystem
    AdobeFlashPlayerUpdateSvc          Adobe Flash Player Update Service                                       FlashPlayerUpdateService.exe  17.0.0.134                     LocalSystem
    AeLookupSvc                                                              svchost.exe           6.1.7600.16385                       localSystem
    ALG                                                                             alg.exe               6.1.7600.16385                 NT AUTHORITY\LocalService
    AppIDSvc                                                                            svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    AppMgmt                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    aspnet_state                         ASP.NET                                                aspnet_state.exe      4.0.30319.34209                NT AUTHORITY\NetworkService
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           6.1.7600.16385                       LocalSystem
    AudioSrv                           Windows Audio                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           6.1.7600.16385                       LocalSystem
    BDESVC                                BitLocker                                      svchost.exe           6.1.7600.16385                       localSystem
    BFE                                                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           6.1.7600.16385                       LocalSystem
    Browser                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    bthserv                              Bluetooth                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    c2cautoupdatesvc                   Skype Click to Call Updater                                             SkypeC2CAutoUpdateSvc.exe  7.3.16540.9015                 LocalSystem
    c2cpnrsvc                          Skype Click to Call PNR Service                                         SkypeC2CPNRSvc.exe    7.3.16540.9015                 NT AUTHORITY\NetworkService
    CertPropSvc                                                                      svchost.exe           6.1.7600.16385                       LocalSystem
    clr_optimization_v2.0.50727_32     Microsoft .NET Framework NGEN v2.0.50727_X86                            mscorsvw.exe          2.0.50727.4927                 LocalSystem
    clr_optimization_v2.0.50727_64     Microsoft .NET Framework NGEN v2.0.50727_X64                            mscorsvw.exe          2.0.50727.4927                 LocalSystem
    clr_optimization_v4.0.30319_32     Microsoft .NET Framework NGEN v4.0.30319_X86                            mscorsvw.exe          4.0.30319.34209                LocalSystem
    clr_optimization_v4.0.30319_64     Microsoft .NET Framework NGEN v4.0.30319_X64                            mscorsvw.exe          4.0.30319.34209                LocalSystem
    COMSysApp                            COM+                                               dllhost.exe           6.1.7600.16385                 LocalSystem
    CryptSvc                                                                                 svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    CscService                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           6.1.7600.16385                       LocalSystem
    defragsvc                                                                               svchost.exe           6.1.7600.16385                 localSystem
    Dhcp                               DHCP-                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Dnscache                           DNS-                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    dot3svc                                                                              svchost.exe           6.1.7600.16385                       localSystem
    DPS                                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EapHost                                (EAP)                         svchost.exe           6.1.7600.16385                       localSystem
    EFS                                   (EFS)                                      lsass.exe             6.1.7601.17725                       LocalSystem
    ehRecvr                              Windows Media Center                                    ehRecvr.exe           6.1.7601.17514                 NT AUTHORITY\networkService
    ehSched                              Windows Media Center                                ehsched.exe           6.1.7600.16385                 NT AUTHORITY\networkService
    EhttpSrv                           ESET HTTP Server                                                        EHttpSrv.exe          4.2.67.10                      NT AUTHORITY\NetworkService
    ekrn                               ESET Service                                                            ekrn.exe              4.2.67.10                      LocalSystem
    eventlog                             Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    fdPHost                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache                             Windows                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.5011                  NT Authority\LocalService
    gpsvc                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    gupdate                              Google (gupdate)                                       GoogleUpdate.exe      1.3.21.103                     LocalSystem
    gupdatem                             Google (gupdatem)                                      GoogleUpdate.exe      1.3.21.103                     LocalSystem
    hidserv                              HID-                                                svchost.exe           6.1.7600.16385                       LocalSystem
    hkmsvc                                                      svchost.exe           6.1.7600.16385                       localSystem
    HomeGroupListener                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    HomeGroupProvider                                                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    idsvc                              Windows CardSpace                                                       infocard.exe          3.0.4506.5420                        LocalSystem
    IKEEXT                               IPsec        IP     svchost.exe           6.1.7600.16385                       LocalSystem
    IPBusEnum                           IP- PnP-X                                              svchost.exe           6.1.7600.16385                       LocalSystem
    iphlpsvc                             IP                                               svchost.exe           6.1.7600.16385                       LocalSystem
    KeyIso                               CNG                                                     lsass.exe             6.1.7601.17725                       LocalSystem
    KtmRm                              KtmRm                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    LanmanWorkstation                                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    lltdsvc                                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Mcx2Svc                              Media Center                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MMCSS                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    MozillaMaintenance                 Mozilla Maintenance Service                                             maintenanceservice.exe  38.0.1.5611                    LocalSystem
    MpsSvc                              Windows                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MSDTC                                                                   msdtc.exe             2001.12.8530.16385                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           6.1.7600.16385                       LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.7601.17514                 LocalSystem
    napagent                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Netlogon                                                                                lsass.exe             6.1.7601.17725                       LocalSystem
    Netman                                                                                   svchost.exe           6.1.7600.16385                       LocalSystem
    NetMsmqActivator                     Net.Msmq                                         SMSvcHost.exe         4.0.30319.34209                      NT AUTHORITY\NetworkService
    NetPipeActivator                     Net.Pipe                                         SMSvcHost.exe         4.0.30319.34209                      NT AUTHORITY\LocalService
    netprofm                                                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    NetTcpActivator                      Net.Tcp                                          SMSvcHost.exe         4.0.30319.34209                      NT AUTHORITY\LocalService
    NetTcpPortSharing                       Net.Tcp                                  SMSvcHost.exe         4.0.30319.34209                      NT AUTHORITY\LocalService
    NlaSvc                                                                     svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    nvsvc                              NVIDIA Display Driver Service                                           nvvsvc.exe            8.17.13.5286                   LocalSystem
    ose                                Office Source Engine                                                    OSE.EXE               11.0.5525.0                    LocalSystem
    p2pimsvc                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    PerfHost                                                           perfhost.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    pla                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PlugPlay                           Plug-and-Play                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    PnkBstrA                           PnkBstrA                                                                PnkBstrA.exe                                         LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Power                                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    ProfSvc                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    ProtectedStorage                                                                        lsass.exe             6.1.7601.17725                       LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           6.1.7600.16385                       localSystem
    RasMan                                                                svchost.exe           6.1.7600.16385                       localSystem
    RemoteAccess                                                                  svchost.exe           6.1.7600.16385                       localSystem
    RemoteRegistry                                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RpcEptMapper                          RPC                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           6.1.7600.16385                 NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    SamSs                                                                   lsass.exe             6.1.7601.17725                       LocalSystem
    SCardSvr                           -                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Schedule                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    SCPolicySvc                          -                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SDRSVC                              Windows                                                       svchost.exe           6.1.7600.16385                 localSystem
    seclogon                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    SENS                                                                    svchost.exe           6.1.7600.16385                       LocalSystem
    SensrSvc                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           6.1.7600.16385                       localSystem
    SharedAccess                             (ICS)                            svchost.exe           6.1.7600.16385                       LocalSystem
    ShellHWDetection                                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SNMPTRAP                            SNMP                                                            snmptrap.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           6.1.7601.17777                 LocalSystem
    sppsvc                                                                        sppsvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    sppuinotify                          SPP                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SSDPSRV                             SSDP                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SstpSvc                             SSTP                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    stisvc                                Windows (WIA)                               svchost.exe           6.1.7600.16385                 NT Authority\LocalService
    swprv                                  (Microsoft)                  svchost.exe           6.1.7600.16385                 LocalSystem
    SysMain                            Superfetch                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    TabletInputService                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TapiSrv                                                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    TBS                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TermService                                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    THREADORDER                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TrkWks                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  6.1.7601.17514                 localSystem
    TuneUp.UtilitiesSvc                TuneUp Utilities Service                                                TuneUpUtilitiesService64.exe  12.0.3600.114                  LocalSystem
    UFDSVC                             UFD Command Service                                                     ufdsvc.exe            1.0.0.7                        LocalSystem
    UI0Detect                                                                     UI0Detect.exe         6.1.7600.16385                 LocalSystem
    UmRdpService                                svchost.exe           6.1.7600.16385                       localSystem
    upnphost                             PNP-                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    UxSms                                                           svchost.exe           6.1.7600.16385                       localSystem
    VaultSvc                                                                             lsass.exe             6.1.7601.17725                       LocalSystem
    vds                                                                                         vds.exe               6.1.7601.17514                 LocalSystem
    VSS                                                                                  vssvc.exe             6.1.7601.17514                 LocalSystem
    W32Time                              Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    wbengine                                                                wbengine.exe          6.1.7601.17514                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wcncsvc                              Windows -                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WcsPlugInService                     Windows (WCS)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WebClient                          -                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    wercplsupport                          "     "  svchost.exe           6.1.7600.16385                       localSystem
    WerSvc                                Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinDefend                           Windows                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Wlansvc                              WLAN                                               svchost.exe           6.1.7600.16385                       LocalSystem
    wmiApSrv                           WMI Performance Adapter                                                 WmiApSrv.exe          6.1.7600.16385                 localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe                                         NT AUTHORITY\NetworkService
    WPCSvc                             Parental Controls                                                       svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    WPDBusEnum                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wscsvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.7601.17610                 LocalSystem
    wuauserv                             Windows                                                svchost.exe           6.1.7600.16385                       LocalSystem
    wudfsvc                            Windows Driver Foundation - User-mode Driver Framework                  svchost.exe           6.1.7600.16385                       LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService


--------[  DLL ]---------------------------------------------------------------------------------------------------

    aaclient.dll               6.1.7601.18079                  
    accessibilitycpl.dll       6.1.7601.17514                 
    acctres.dll                6.1.7600.16385                     (Microsoft)
    acledit.dll                6.1.7600.16385                 ACL
    aclui.dll                  6.1.7600.16385                
    acppage.dll                6.1.7601.17514                  ""
    actioncenter.dll           6.1.7601.17514               
    actioncentercpl.dll        6.1.7601.17514                 
    activeds.dll               6.1.7601.17514               DLL   AD
    actxprxy.dll               6.1.7601.17514              ActiveX Interface Marshaling Library
    admparse.dll               8.0.7600.16385              IEAK Global Policy Template Parser
    admtmpl.dll                6.1.7601.17514               " "
    adprovider.dll             6.1.7600.16385               DLL adprovider
    adsldp.dll                 6.1.7601.17514              ADs LDAP Provider DLL
    adsldpc.dll                6.1.7600.16385               DLL  LDAP AD
    adsmsext.dll               6.1.7600.16385              ADs LDAP Provider DLL
    adsnt.dll                  6.1.7600.16385               DLL    Windows NT
    adtschema.dll              6.1.7600.16385                 
    advapi32.dll               6.1.7601.18247                API Windows 32
    advpack.dll                8.0.7600.16385              ADVPACK
    aecache.dll                6.1.7600.16385              AECache Sysprep Plugin
    aeevts.dll                 6.1.7600.16385                  
    alttab.dll                 6.1.7600.16385              Windows Shell Alt Tab
    amstream.dll               6.6.7601.17514              DirectShow Runtime.
    amxread.dll                6.1.7600.16385              API Tracing Manifest Read Library
    apds.dll                   6.1.7600.16385                  Microsoft
    apihook.dll                                            
    apilogen.dll               6.1.7600.16385                 API
    api-ms-win-core-console-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-file-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-handle-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-heap-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-localization-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-localregistry-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-misc-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-profile-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-string-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-synch-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-util-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-security-base-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-sddl-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l2-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    apircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    apisetschema.dll           6.1.7601.18229              ApiSet Schema DLL
    apphelp.dll                6.1.7601.17514                 
    apphlpdm.dll               6.1.7600.16385                 
    appidapi.dll               6.1.7600.16385               API-  
    appidpolicyengineapi.dll   6.1.7600.16385              AppId Policy Engine API Module
    appmgmts.dll               6.1.7600.16385                
    appmgr.dll                 6.1.7601.17514                 
    apss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    asferror.dll               12.0.7600.16385               ASF
    aspnet_counters.dll        4.0.30319.34209             Microsoft ASP.NET Performance Counter Shim DLL
    asycfilt.dll               6.1.7601.17514              
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atl100.dll                 10.0.40219.1                ATL Module for Windows
    atl110.dll                 11.0.60610.1                ATL Module for Windows
    atmfd.dll                  5.1.2.238                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.238                   Windows NT OpenType/Type 1 API Library.
    audiodev.dll               6.1.7601.17514                   
    audioeng.dll               6.1.7600.16385              Audio Engine
    audiokse.dll               6.1.7600.16385              Audio Ks Endpoint
    audioses.dll               6.1.7601.17514                
    auditnativesnapin.dll      6.1.7600.16385                    
    auditpolicygpinterop.dll   6.1.7600.16385                 
    auditpolmsg.dll            6.1.7600.16385                MMC  
    authfwcfg.dll              6.1.7600.16385               Windows      
    authfwgp.dll               6.1.7600.16385               Windows c      
    authfwsnapin.dll           6.1.7601.17514              Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           6.1.7600.16385              Wizard Framework
    authui.dll                 6.1.7601.18103                
    authz.dll                  6.1.7600.16385              Authorization Framework
    autoplay.dll               6.1.7601.17514               ( )
    auxiliarydisplayapi.dll    6.1.7600.16385              Microsoft Windows SideShow API
    auxiliarydisplaycpl.dll    6.1.7601.17514                Microsoft Windows SideShow
    avicap32.dll               6.1.7600.16385                 AVI
    avifil32.dll               6.1.7601.17514                 AVI
    avrt.dll                   6.1.7600.16385              Multimedia Realtime Runtime
    azroles.dll                6.1.7601.17514              azroles Module
    azroleui.dll               6.1.7601.17514               
    azsqlext.dll               6.1.7601.17514              AzMan Sql Audit Extended Stored Procedures Dll
    basecsp.dll                6.1.7601.17514                 - (Microsoft)
    batmeter.dll               6.1.7601.17514              Battery Meter Helper DLL
    bcrypt.dll                 6.1.7600.16385              Windows Cryptographic Primitives Library (Wow64)
    bcryptprimitives.dll       6.1.7600.16385              Windows Cryptographic Primitives Library
    bidispl.dll                6.1.7600.16385              Bidispl DLL
    biocredprov.dll            6.1.7600.16385                 WinBio
    bitsperf.dll               7.5.7601.17514              Perfmon Counter Access
    bitsprx2.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    bitsprx3.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.0 Proxy
    bitsprx4.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.5 Proxy
    bitsprx5.dll               7.5.7600.16385              Background Intelligent Transfer Service 3.0 Proxy
    bitsprx6.dll               7.5.7600.16385              Background Intelligent Transfer Service 4.0 Proxy
    bjablr32.dll               11.0.5510.0                 Outlook LDAP Address Book Provider
    blackbox.dll               11.0.7601.17514             BlackBox DLL
    bootvid.dll                6.1.7600.16385              VGA Boot Driver
    browcli.dll                6.1.7601.17887              Browser Service Client DLL
    browseui.dll               6.1.7601.17514              Shell Browser UI Library
    btpanui.dll                6.1.7600.16385                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    bwunpairelevated.dll       6.1.7600.16385              BWUnpairElevated Proxy Dll
    c_g18030.dll               6.1.7600.16385              GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               6.1.7600.16385              ISO-2022 Code Page Translation DLL
    c_iscii.dll                6.1.7601.17514              ISCII Code Page Translation DLL
    cabinet.dll                6.1.7601.17514              Microsoft Cabinet File API
    cabview.dll                6.1.7601.17514                 CAB-
    capiprovider.dll           6.1.7600.16385               DLL capiprovider
    capisp.dll                 6.1.7600.16385              Sysprep cleanup dll for CAPI
    catsrv.dll                 2001.12.8530.16385          COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Utilities
    cca.dll                    6.6.7601.17514              CCA DirectShow Filter.
    cdosys.dll                 6.6.7601.17857              Microsoft CDO for Windows Library
    certcli.dll                6.1.7601.17514                 Microsoft Active Directory
    certcredprovider.dll       6.1.7600.16385                 
    certenc.dll                6.1.7601.18151              Active Directory Certificate Services Encoding
    certenroll.dll             6.1.7601.17514                  Active Directory Microsoft
    certenrollui.dll           6.1.7600.16385                  X509
    certmgr.dll                6.1.7601.17514                
    certpoleng.dll             6.1.7601.17514                
    cewmdm.dll                 12.0.7600.16385               Windows CE WMDM
    cfgbkend.dll               6.1.7600.16385              Configuration Backend Interface
    cfgmgr32.dll               6.1.7601.17621              Configuration Manager DLL
    checkactivate.dll          1.0.0.4                     checkactivate
    checkcommon.dll            1.0.0.4                     checkactivate
    chsbrkr.dll                6.1.7600.16385              Simplified Chinese Word Breaker
    chtbrkr.dll                6.1.7600.16385              Chinese Traditional Word Breaker
    chxreadingstringime.dll    6.1.7600.16385              CHxReadingStringIME
    cic.dll                    6.1.7600.16385                CIC - MMC   
    clb.dll                    6.1.7600.16385                
    clbcatq.dll                2001.12.8530.16385          COM+ Configuration Catalog
    clfsw32.dll                6.1.7600.16385              Common Log Marshalling Win32 DLL
    cliconfg.dll               6.1.7600.16385              SQL Client Configuration Utility DLL
    clusapi.dll                6.1.7601.17514               API 
    cmcfg32.dll                7.2.7600.16385                  Microsoft
    cmdial32.dll               7.2.7600.16385               
    cmicryptinstall.dll        6.1.7600.16385              Installers for cryptographic elements of CMI objects
    cmifw.dll                  6.1.7600.16385              Windows Firewall rule configuration plug-in
    cmipnpinstall.dll          6.1.7600.16385              PNP plugin installer for CMI
    cmlua.dll                  7.2.7600.16385                API   
    cmpbk32.dll                7.2.7600.16385              Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.7600.16385                API      
    cmutil.dll                 7.2.7600.16385                  (Microsoft)
    cngaudit.dll               6.1.7600.16385              Windows Cryptographic Next Generation audit library
    cngprovider.dll            6.1.7600.16385               DLL cngprovider
    cnvfat.dll                 6.1.7600.16385              FAT File System Conversion Utility DLL
    colbact.dll                2001.12.8530.16385          COM+
    colorcnv.dll               6.1.7600.16385              Windows Media Color Conversion
    colorui.dll                6.1.7600.16385                 
    comcat.dll                 6.1.7600.16385              Microsoft Component Category Manager Library
    comctl32.dll               5.82.7601.18201                  
    comdlg32.dll               6.1.7601.17514                 
    compobj.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    compstui.dll               6.1.7600.16385                   
    comrepl.dll                2001.12.8530.16385          COM+
    comres.dll                 2001.12.8530.16385           COM+
    comsnap.dll                2001.12.8530.16385          COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.8530.16385          COM+ Services
    comuid.dll                 2001.12.8530.16385          COM+ Explorer UI
    connect.dll                6.1.7600.16385               
    console.dll                6.1.7600.16385                 
    contab32.dll               11.0.5510.0                 Outlook Address Book Service
    corpol.dll                 8.0.7600.16385              Microsoft COM Runtime Execution Engine
    cpfilters.dll              6.6.7601.17528               PTFilter & Encypter/Decrypter Tagger Filters.
    credssp.dll                6.1.7601.17514              Credential Delegation Security Package
    credui.dll                 6.1.7601.17514                 
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                6.1.7601.18205              API32 
    cryptbase.dll              6.1.7600.16385              Base cryptographic API DLL
    cryptdlg.dll               6.1.7601.18150                
    cryptdll.dll               6.1.7600.16385              Cryptography Manager
    cryptext.dll               6.1.7600.16385                
    cryptnet.dll               6.1.7601.18205              Crypto Network Related API
    cryptsp.dll                6.1.7600.16385              Cryptographic Service Provider API
    cryptsvc.dll               6.1.7601.18205               
    cryptui.dll                6.1.7601.17514                
    cryptxml.dll               6.1.7600.16385              API- XML DigSig
    cscapi.dll                 6.1.7601.17514              Offline Files Win32 API
    cscdll.dll                 6.1.7601.17514              Offline Files Temporary Shim
    cscobj.dll                 6.1.7601.17514               COM-   CSC API
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    d2d1.dll                   6.1.7601.17514              Microsoft D2D Library
    d3d10.dll                  6.1.7600.16385              Direct3D 10 Runtime
    d3d10_1.dll                6.1.7600.16385              Direct3D 10.1 Runtime
    d3d10_1core.dll            6.1.7601.17514              Direct3D 10.1 Runtime
    d3d10core.dll              6.1.7600.16385              Direct3D 10 Runtime
    d3d10level9.dll            6.1.7601.17514              Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              6.1.7601.17514              Direct3D 10 Rasterizer
    d3d11.dll                  6.1.7601.17514              Direct3D 11 Runtime
    d3d8.dll                   6.1.7600.16385              Microsoft Direct3D
    d3d8thk.dll                6.1.7600.16385              Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   6.1.7601.17514              Direct3D 9 Runtime
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  6.1.7600.16385              Microsoft Direct3D
    d3dim700.dll               6.1.7600.16385              Microsoft Direct3D
    d3dramp.dll                6.1.7600.16385              Microsoft Direct3D
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 6.1.7600.16385              DirectX Files DLL
    dataclen.dll               6.1.7600.16385                 Windows
    davclnt.dll                6.1.7601.18201              Web DAV Client DLL
    davhlpr.dll                6.1.7600.16385              DAV Helper DLL
    dbgeng.dll                 6.1.7601.17514              Windows Symbolic Debugger Engine
    dbghelp.dll                6.1.7601.17514              Windows Image Helper
    dbnetlib.dll               6.1.7600.16385              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               6.1.7600.16385              Named Pipes Net DLL for SQL Clients
    dciman32.dll               6.1.7601.18177              DCI Manager
    ddaclsys.dll               6.1.7600.16385              SysPrep module for Reseting Data Drive ACL 
    ddoiproxy.dll              6.1.7600.16385              DDOI Interface Proxy
    ddores.dll                 6.1.7600.16385                  
    ddraw.dll                  6.1.7600.16385              Microsoft DirectDraw
    ddrawex.dll                6.1.7600.16385              Direct Draw Ex
    defaultlocationcpl.dll     6.1.7601.17514               :   
    deskadp.dll                6.1.7600.16385                 
    deskmon.dll                6.1.7600.16385                
    deskperf.dll               6.1.7600.16385                
    devenum.dll                6.6.7600.16385               .
    devicecenter.dll           6.1.7601.17514                
    devicedisplaystatusmanager.dll  6.1.7600.16385              Device Display Status Manager
    devicemetadataparsers.dll  6.1.7600.16385              Common Device Metadata parsers
    devicepairing.dll          6.1.7600.16385               ,   
    devicepairingfolder.dll    6.1.7601.17514                 
    devicepairinghandler.dll   6.1.7600.16385              Device Pairing Handler Dll
    devicepairingproxy.dll     6.1.7600.16385              Device Pairing Proxy Dll
    deviceuxres.dll            6.1.7600.16385              Windows Device User Experience Resource File
    devmgr.dll                 6.1.7600.16385                 
    devobj.dll                 6.1.7601.17621              Device Information Set DLL
    devrtl.dll                 6.1.7601.17621              Device Management Run Time Library
    dfscli.dll                 6.1.7600.16385              Windows NT Distributed File System Client DLL
    dfshim.dll                 4.0.40305.0                     ClickOnce
    dfsshlex.dll               6.1.7600.16385                   DFS
    dhcpcmonitor.dll           6.1.7600.16385               (DLL)   DHCP
    dhcpcore.dll               6.1.7601.17514               DHCP-
    dhcpcore6.dll              6.1.7601.17970               DHCPv6
    dhcpcsvc.dll               6.1.7600.16385               DHCP-
    dhcpcsvc6.dll              6.1.7601.17970               DHCPv6
    dhcpqec.dll                6.1.7600.16385                   Microsoft DHCP
    dhcpsapi.dll               6.1.7600.16385               API  DHCP-c
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                6.1.7600.16385               DLL  DIMS
    dimsroam.dll               6.1.7600.16385               DLL  DIMS  
    dinput.dll                 6.1.7600.16385              Microsoft DirectInput
    dinput8.dll                6.1.7600.16385              Microsoft DirectInput
    directdb.dll               6.1.7600.16385              Microsoft Direct Database API
    diskcopy.dll               6.1.7600.16385              Windows DiskCopy
    dispex.dll                 5.8.7600.16385              Microsoft  DispEx
    display.dll                6.1.7601.17514                
    dmband.dll                 6.1.7600.16385              Microsoft DirectMusic Band
    dmcompos.dll               6.1.7600.16385              Microsoft DirectMusic Composer
    dmdlgs.dll                 6.1.7600.16385              Disk Management Snap-in Dialogs
    dmdskmgr.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dmdskres.dll               6.1.7600.16385                 
    dmdskres2.dll              6.1.7600.16385                 
    dmime.dll                  6.1.7600.16385              Microsoft DirectMusic Interactive Engine
    dmintf.dll                 6.1.7600.16385              Disk Management DCOM Interface Stub
    dmloader.dll               6.1.7600.16385              Microsoft DirectMusic Loader
    dmocx.dll                  6.1.7600.16385              TreeView OCX
    dmrc.dll                   6.1.7600.16385              Windows MRC
    dmscript.dll               6.1.7600.16385              Microsoft DirectMusic Scripting
    dmstyle.dll                6.1.7600.16385              Microsoft DirectMusic Style Engline
    dmsynth.dll                6.1.7600.16385              Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 6.1.7600.16385                Microsoft DirectMusic
    dmutil.dll                 6.1.7600.16385                 
    dmvdsitf.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dnsapi.dll                 6.1.7601.17570                API DNS-
    dnscmmc.dll                6.1.7601.17514               DLL  DNS  MMC
    docprop.dll                6.1.7600.16385                OLE
    dot3api.dll                6.1.7601.17514              802.3 Autoconfiguration API
    dot3cfg.dll                6.1.7601.17514               Netsh  802.3
    dot3dlg.dll                6.1.7600.16385                UI  802.3
    dot3gpclnt.dll             6.1.7600.16385                   802.3
    dot3gpui.dll               6.1.7600.16385               "   802.3"
    dot3hc.dll                 6.1.7600.16385                 Dot3
    dot3msm.dll                6.1.7601.17514                   802.3
    dot3ui.dll                 6.1.7601.17514                802.3
    dpapiprovider.dll          6.1.7600.16385               DLL dpapiprovider
    dplayx.dll                 6.1.7600.16385              Microsoft DirectPlay
    dpmodemx.dll               6.1.7600.16385                      DirectPlay
    dpnaddr.dll                6.1.7601.17514              Microsoft DirectPlay8 Address
    dpnathlp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPnP
    dpnet.dll                  6.1.7601.17989              Microsoft DirectPlay
    dpnhpast.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPNP
    dpnlobby.dll               6.1.7600.16385              Microsoft DirectPlay8 Lobby
    dpwsockx.dll               6.1.7600.16385                  TCP/IP  IPX  DirectPlay
    dpx.dll                    6.1.7601.17514              Microsoft(R) Delta Package Expander
    drmmgrtn.dll               11.0.7601.17514             DRM Migration DLL
    drmv2clt.dll               11.0.7600.16385             DRMv2 Client DLL
    drprov.dll                 6.1.7600.16385                   ,        ()
    drt.dll                    6.1.7600.16385                
    drtprov.dll                6.1.7600.16385              Distributed Routing Table Providers
    drttransport.dll           6.1.7600.16385              Distributed Routing Table Transport Provider
    drvstore.dll               6.1.7601.17514              Driver Store API
    ds32gt.dll                 6.1.7600.16385              ODBC Driver Setup Generic Thunk
    dsauth.dll                 6.1.7601.17514              DS Authorization for Services
    dsdmo.dll                  6.1.7600.16385              DirectSound Effects
    dshowrdpfilter.dll         1.0.0.0                           ()
    dskquota.dll               6.1.7600.16385               DLL    Windows
    dskquoui.dll               6.1.7601.17514               DLL   
    dsound.dll                 6.1.7600.16385              DirectSound
    dsprop.dll                 6.1.7600.16385                Active Directory
    dsquery.dll                6.1.7600.16385                 
    dsrole.dll                 6.1.7600.16385              DS Role Client DLL
    dssec.dll                  6.1.7600.16385                 
    dssenh.dll                 6.1.7600.16385              Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsuiext.dll                6.1.7601.17514                 
    dswave.dll                 6.1.7600.16385              Microsoft DirectMusic Wave
    dtsh.dll                   6.1.7600.16385               API     
    dui70.dll                  6.1.7600.16385               DirectUI Windows
    dumpster.dll               11.0.5510.0                 Outlook Deleted Item Recovery Client Extension
    duser.dll                  6.1.7600.16385              Windows DirectUser Engine
    dwmapi.dll                 6.1.7600.16385               API     ()
    dwmcore.dll                6.1.7601.17514                Microsoft DWM
    dwrite.dll                 6.1.7601.18245               Microsoft DirectX Typography
    dxdiagn.dll                6.1.7601.17514                Microsoft DirectX
    dxgi.dll                   6.1.7601.17514              DirectX Graphics Infrastructure
    dxmasf.dll                 12.0.7601.17514             Microsoft Windows Media Component Removal File.
    dxptaskringtone.dll        6.1.7601.17514                 Microsoft
    dxptasksync.dll            6.1.7601.17514               Microsoft Windows DXP
    dxtmsft.dll                8.0.7600.16385              DirectX Media -- Image DirectX Transforms
    dxtrans.dll                8.0.7600.16385              DirectX Media -- DirectX Transform Core
    dxva2.dll                  6.1.7600.16385              DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               6.1.7601.17514              Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                6.1.7600.16385                EAP
    eappgnui.dll               6.1.7601.17514                 EAP
    eapphost.dll               6.1.7601.17514                 EAPHost 
    eappprxy.dll               6.1.7600.16385              Microsoft EAPHost Peer Client DLL
    eapqec.dll                 6.1.7600.16385                   Microsoft EAP
    efsadu.dll                 6.1.7600.16385                
    efscore.dll                6.1.7601.17514              EFS Core Library
    efsutil.dll                6.1.7600.16385              EFS Utility Library
    ehstorapi.dll              6.1.7601.17514              Windows Enhanced Storage API
    ehstorpwdmgr.dll           6.1.7600.16385                Windows Enhanced Storage
    ehstorshell.dll            6.1.7600.16385               DLL   Windows Enhanced Storage
    els.dll                    6.1.7600.16385                
    elscore.dll                6.1.7600.16385               DLL   Els
    elslad.dll                 6.1.7600.16385              ELS Language Detection
    elstrans.dll               6.1.7601.17514              ELS Transliteration Service
    emablt32.dll               11.0.5510.0                 Outlook LDAP Address Book Provider
    emsabp32.dll               11.0.5510.0                 Outlook Address Book Provider
    emsmdb32.dll               11.0.5604.0                 Microsoft Exchange Server Information Store Service Provider
    emsui32.dll                11.0.5510.0                 Microsoft Exchange Configuration Library
    encapi.dll                 6.1.7600.16385              Encoder API
    encdec.dll                 6.6.7601.17708                XDS     .
    eqossnap.dll               6.1.7600.16385                EQoS
    es.dll                     2001.12.8530.16385          COM+
    esconf.dll                 5.5.1960.0                  Microsoft Exchange Event Service Config Object
    esent.dll                  6.1.7601.17577                  ESE  Microsoft(R) Windows(R)
    esentprf.dll               6.1.7600.16385              Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    eventcls.dll               6.1.7600.16385              Microsoft Volume Shadow Copy Service event class
    evr.dll                    6.1.7601.17514                DLL   
    explorerframe.dll          6.1.7601.17514              ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    f3ahvoas.dll               6.1.7600.16385              JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               6.1.7601.17514                     Windows
    fdbth.dll                  6.1.7600.16385              Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             6.1.7600.16385              Bluetooth Provider Proxy Dll
    fde.dll                    6.1.7601.17514                 
    fdeploy.dll                6.1.7601.17514                  
    fdpnp.dll                  6.1.7600.16385              Pnp Provider Dll
    fdproxy.dll                6.1.7600.16385              Function Discovery Proxy Dll
    fdssdp.dll                 6.1.7600.16385              Function Discovery SSDP Provider Dll
    fdwcn.dll                  6.1.7600.16385              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 6.1.7600.16385              Function Discovery WNet Provider Dll
    fdwsd.dll                  6.1.7600.16385              Function Discovery WS Discovery Provider Dll
    feclient.dll               6.1.7600.16385              Windows NT File Encryption Client Interfaces
    ff_vfw.dll                                             
    filemgmt.dll               6.1.7600.16385                 
    findnetprinters.dll        6.1.7600.16385              Find Network Printers COM Component
    firewallapi.dll            6.1.7600.16385              API  Windows
    firewallcontrolpanel.dll   6.1.7601.17514                -  Windows
    fltlib.dll                 6.1.7600.16385               
    fm20.dll                   11.0.5601.0                 Microsoft Forms DLL
    fm20enu.dll                11.0.5510.0                 Microsoft Forms International DLL
    fmifs.dll                  6.1.7600.16385              FM IFS Utility DLL
    fms.dll                    1.1.6000.16384                
    fontext.dll                6.1.7601.17514                Windows
    fontsub.dll                6.1.7601.18177              Font Subsetting DLL
    fphc.dll                   6.1.7601.17514               Filtering Platform Helper
    framedyn.dll               6.1.7601.17514              WMI SDK Provider Framework
    framedynos.dll             6.1.7601.17514              WMI SDK Provider Framework
    fthsvc.dll                 6.1.7600.16385                  Microsoft Windows
    fundisc.dll                6.1.7600.16385              DLL  
    fwcfg.dll                  6.1.7600.16385                  Windows
    fwpuclnt.dll               6.1.7601.17514              API   FWP/IPsec
    fwremotesvr.dll            6.1.7600.16385              Windows Firewall Remote APIs Server
    gameux.dll                 6.1.7601.18020               
    gameuxlegacygdfs.dll       1.0.0.1                     Legacy GDF resource DLL
    gapi32.dll                 11.0.4123.0                 Microsoft Mail Configuration Library
    gcdef.dll                  6.1.7600.16385                   
    gdi32.dll                  6.1.7601.17514              GDI Client DLL
    gdiplus.dll                6.1.7601.18120              Microsoft GDI+
    getcur.dll                                             
    getuname.dll               6.1.7600.16385                   UCE
    glmf32.dll                 6.1.7600.16385              OpenGL Metafiling DLL
    glu32.dll                  6.1.7600.16385                OpenGL
    gpapi.dll                  6.1.7600.16385                API  
    gpedit.dll                 6.1.7600.16385              GPEdit
    gpprefcl.dll               6.1.7601.17514                 
    gpprnext.dll               6.1.7600.16385                 
    gpscript.dll               6.1.7600.16385                
    gptext.dll                 6.1.7600.16385              GPTExt
    hash2.dll                  7.0.0.0                     
    hbaapi.dll                 6.1.7601.17514              HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            6.1.7600.16385                
    helppaneproxy.dll          6.1.7600.16385              Microsoft Help Proxy
    hgcpl.dll                  6.1.7601.17514                 
    hhsetup.dll                6.1.7600.16385              Microsoft HTML Help
    hid.dll                    6.1.7600.16385                HID
    hidserv.dll                6.1.7600.16385               HID
    hlink.dll                  6.1.7600.16385               Microsoft Office 2000
    hnetcfg.dll                6.1.7600.16385                 
    hnetmon.dll                6.1.7600.16385              DLL   
    httpapi.dll                6.1.7601.17514              HTTP Protocol Stack API
    htui.dll                   6.1.7600.16385                  
    ias.dll                    6.1.7600.16385                 (NPS)
    iasacct.dll                6.1.7601.17514                NPS
    iasads.dll                 6.1.7600.16385                Active Directory NPS
    iasdatastore.dll           6.1.7600.16385              NPS Datastore server
    iashlpr.dll                6.1.7600.16385                NPS
    iasmigplugin.dll           6.1.7600.16385              NPS Migration DLL
    iasnap.dll                 6.1.7600.16385              NPS NAP Provider
    iaspolcy.dll               6.1.7600.16385              NPS Pipeline
    iasrad.dll                 6.1.7601.17514                RADIUS NPS
    iasrecst.dll               6.1.7601.17514              NPS XML Datastore Access
    iassam.dll                 6.1.7600.16385              NPS NT SAM Provider
    iassdo.dll                 6.1.7600.16385               SDO NPS
    iassvcs.dll                6.1.7600.16385                NPS
    icardie.dll                8.0.7600.16385              Microsoft Information Card IE Helper
    icardres.dll               3.0.4506.4926               Windows CardSpace
    iccvid.dll                 1.10.0.13                    Cinepak
    icm32.dll                  6.1.7600.16385              Microsoft Color Management Module (CMM)
    icmp.dll                   6.1.7600.16385              ICMP DLL
    icmui.dll                  6.1.7600.16385                  
    iconcodecservice.dll       6.1.7600.16385              Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 6.1.7600.16385                 
    idndl.dll                  6.1.7600.16385              Downlevel DLL
    idstore.dll                6.1.7600.16385              Identity Store
    ieakeng.dll                8.0.7600.16385                  Internet Explorer
    ieaksie.dll                8.0.7600.16385                 Internet Explorer   
    ieakui.dll                 8.0.7600.16385                UI DLL Microsoft IEAK
    ieapfltr.dll               8.0.6001.18669              Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.7601.17514               IEAK
    ieframe.dll                8.0.7601.17601              -
    iepeers.dll                8.0.7601.17514              Peer- Internet Explorer
    iernonce.dll               8.0.7600.16385                RunOnce   
    iertutil.dll               8.0.7601.17608              Run time utility for Internet Explorer
    iesetup.dll                8.0.7600.16385                IOD
    iesysprep.dll              8.0.7601.17514              IE Sysprep Provider
    ieui.dll                   8.0.7601.17601                 Internet Explorer
    ifmon.dll                  6.1.7600.16385                IF
    ifsutil.dll                6.1.7601.17514              IFS Utility DLL
    ifsutilx.dll               6.1.7600.16385              IFS Utility Extension DLL
    imagehlp.dll               6.1.7601.17787              Windows NT Image Helper
    imageres.dll               6.1.7600.16385              Windows Image Resource
    imagesp1.dll               6.1.7600.16385              Windows SP1 Image Resource
    imapi.dll                  6.1.7600.16385               Image Mastering API
    imapi2.dll                 6.1.7601.17514              IMAPI  2
    imapi2fs.dll               6.1.7601.17514              Image Mastering File System Imaging API v2
    imgutil.dll                8.0.7601.17514              IE plugin image decoder support DLL
    imjp10k.dll                10.1.7600.16385             Microsoft IME
    imm32.dll                  6.1.7601.17514              Multi-User Windows IMM32 API Client DLL
    inetcomm.dll               6.1.7601.17609              Microsoft Internet Messaging API Resources
    inetmib1.dll               6.1.7601.17514              Microsoft MIB-II subagent
    inetres.dll                6.1.7600.16385               API  
    infocardapi.dll            3.0.4506.4926               Microsoft InfoCards
    inked.dll                  6.1.7600.16385              Microsoft Tablet PC InkEdit Control
    input.dll                  6.1.7601.17514               DLL  
    inseng.dll                 8.0.7601.17514               
    iologmsg.dll               6.1.7600.16385                /
    ipbusenumproxy.dll         6.1.7600.16385              Associated Device Presence Proxy Dll
    iphlpapi.dll               6.1.7601.17514              IP Helper API
    iprop.dll                  6.1.7600.16385              OLE PropertySet Implementation
    iprtprio.dll               6.1.7600.16385              IP Routing Protocol Priority DLL
    iprtrmgr.dll               6.1.7601.17514               IP-
    ipsecsnp.dll               6.1.7600.16385                 IP-
    ipsmsnap.dll               6.1.7601.17514                IP-
    ir32_32.dll                3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_qc.dll                4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    irclass.dll                6.1.7600.16385                 
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               6.1.7600.16385              API-  iSCSI
    iscsied.dll                6.1.7600.16385              iSCSI Extension DLL
    iscsium.dll                6.1.7601.17514              iSCSI Discovery api
    iscsiwmi.dll               6.1.7600.16385              MS iSCSI Initiator WMI Provider
    itircl.dll                 6.1.7601.17514              Microsoft InfoTech IR Local DLL
    itss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    itvdata.dll                6.6.7601.17514              iTV Data Filters.
    iyuv_32.dll                6.1.7601.17514              Intel Indeo(R) Video YUV 
    jscript.dll                5.8.7601.17866              Microsoft (R) JScript
    jsproxy.dll                8.0.7601.17601              JScript Proxy Auto-Configuration
    kbd101.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 101
    kbd101a.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout for 103
    kbd106.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbd106n.dll                6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbda1.dll                  6.1.7600.16385              Arabic_English_101 Keyboard Layout
    kbda2.dll                  6.1.7600.16385              Arabic_2 Keyboard Layout
    kbda3.dll                  6.1.7600.16385              Arabic_French_102 Keyboard Layout
    kbdal.dll                  6.1.7600.16385              Albania Keyboard Layout
    kbdarme.dll                6.1.7600.16385              Eastern Armenian Keyboard Layout
    kbdarmw.dll                6.1.7600.16385              Western Armenian Keyboard Layout
    kbdax2.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 6.1.7600.16385              Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                6.1.7600.16385              Azeri-Latin Keyboard Layout
    kbdbash.dll                6.1.7601.17514              Bashkir Keyboard Layout
    kbdbe.dll                  6.1.7600.16385              Belgian Keyboard Layout
    kbdbene.dll                6.1.7600.16385              Belgian Dutch Keyboard Layout
    kbdbgph.dll                6.1.7600.16385              Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               6.1.7600.16385              Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 6.1.7600.16385              Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 6.1.7601.17514              Belarusian Keyboard Layout
    kbdbr.dll                  6.1.7600.16385              Brazilian Keyboard Layout
    kbdbu.dll                  6.1.7600.16385              Bulgarian (Typewriter) Keyboard Layout
    kbdbulg.dll                6.1.7601.17514              Bulgarian Keyboard Layout
    kbdca.dll                  6.1.7600.16385              Canadian Multilingual Keyboard Layout
    kbdcan.dll                 6.1.7600.16385              Canadian Multilingual Standard Keyboard Layout
    kbdcr.dll                  6.1.7600.16385              Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  6.1.7600.16385              Czech Keyboard Layout
    kbdcz1.dll                 6.1.7601.17514              Czech_101 Keyboard Layout
    kbdcz2.dll                 6.1.7600.16385              Czech_Programmer's Keyboard Layout
    kbdda.dll                  6.1.7600.16385              Danish Keyboard Layout
    kbddiv1.dll                6.1.7600.16385              Divehi Phonetic Keyboard Layout
    kbddiv2.dll                6.1.7600.16385              Divehi Typewriter Keyboard Layout
    kbddv.dll                  6.1.7600.16385              Dvorak US English Keyboard Layout
    kbdes.dll                  6.1.7600.16385              Spanish Alernate Keyboard Layout
    kbdest.dll                 6.1.7600.16385              Estonia Keyboard Layout
    kbdfa.dll                  6.1.7600.16385              Persian Keyboard Layout
    kbdfc.dll                  6.1.7600.16385              Canadian French Keyboard Layout
    kbdfi.dll                  6.1.7600.16385              Finnish Keyboard Layout
    kbdfi1.dll                 6.1.7600.16385              Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  6.1.7600.16385              F?roese Keyboard Layout
    kbdfr.dll                  6.1.7600.16385              French Keyboard Layout
    kbdgae.dll                 6.1.7600.16385              Gaelic Keyboard Layout
    kbdgeo.dll                 6.1.7601.17514              Georgian Keyboard Layout
    kbdgeoer.dll               6.1.7600.16385              Georgian (Ergonomic) Keyboard Layout
    kbdgeoqw.dll               6.1.7600.16385              Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 6.1.7601.17514              Greek_Latin Keyboard Layout
    kbdgr.dll                  6.1.7600.16385              German Keyboard Layout
    kbdgr1.dll                 6.1.7601.17514              German_IBM Keyboard Layout
    kbdgrlnd.dll               6.1.7600.16385              Greenlandic Keyboard Layout
    kbdhau.dll                 6.1.7600.16385              Hausa Keyboard Layout
    kbdhe.dll                  6.1.7600.16385              Greek Keyboard Layout
    kbdhe220.dll               6.1.7600.16385              Greek IBM 220 Keyboard Layout
    kbdhe319.dll               6.1.7600.16385              Greek IBM 319 Keyboard Layout
    kbdheb.dll                 6.1.7600.16385              KBDHEB Keyboard Layout
    kbdhela2.dll               6.1.7600.16385              Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               6.1.7600.16385              Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                6.1.7600.16385              Greek_Polytonic Keyboard Layout
    kbdhu.dll                  6.1.7600.16385              Hungarian Keyboard Layout
    kbdhu1.dll                 6.1.7600.16385              Hungarian 101-key Keyboard Layout
    kbdibm02.dll               6.1.7600.16385              JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 6.1.7600.16385              Igbo Keyboard Layout
    kbdic.dll                  6.1.7600.16385              Icelandic Keyboard Layout
    kbdinasa.dll               6.1.7600.16385              Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               6.1.7600.16385              Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               6.1.7600.16385              Bengali (Inscript) Keyboard Layout
    kbdinben.dll               6.1.7601.17514              Bengali Keyboard Layout
    kbdindev.dll               6.1.7600.16385              Devanagari Keyboard Layout
    kbdinguj.dll               6.1.7600.16385              Gujarati Keyboard Layout
    kbdinhin.dll               6.1.7601.17514              Hindi Keyboard Layout
    kbdinkan.dll               6.1.7601.17514              Kannada Keyboard Layout
    kbdinmal.dll               6.1.7600.16385              Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               6.1.7601.17514              Marathi Keyboard Layout
    kbdinori.dll               6.1.7601.17514              Oriya Keyboard Layout
    kbdinpun.dll               6.1.7600.16385              Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               6.1.7601.17514              Tamil Keyboard Layout
    kbdintel.dll               6.1.7601.17514              Telugu Keyboard Layout
    kbdinuk2.dll               6.1.7600.16385              Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  6.1.7600.16385              Irish Keyboard Layout
    kbdit.dll                  6.1.7600.16385              Italian Keyboard Layout
    kbdit142.dll               6.1.7600.16385              Italian 142 Keyboard Layout
    kbdiulat.dll               6.1.7600.16385              Inuktitut Latin Keyboard Layout
    kbdjpn.dll                 6.1.7600.16385              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 6.1.7600.16385              Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                6.1.7600.16385              Cambodian Standard Keyboard Layout
    kbdkor.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout Stub driver
    kbdkyr.dll                 6.1.7600.16385              Kyrgyz Keyboard Layout
    kbdla.dll                  6.1.7600.16385              Latin-American Spanish Keyboard Layout
    kbdlao.dll                 6.1.7600.16385              Lao Standard Keyboard Layout
    kbdlk41a.dll               6.1.7601.17514              DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  6.1.7600.16385              Lithuania Keyboard Layout
    kbdlt1.dll                 6.1.7601.17514              Lithuanian Keyboard Layout
    kbdlt2.dll                 6.1.7600.16385              Lithuanian Standard Keyboard Layout
    kbdlv.dll                  6.1.7600.16385              Latvia Keyboard Layout
    kbdlv1.dll                 6.1.7600.16385              Latvia-QWERTY Keyboard Layout
    kbdmac.dll                 6.1.7600.16385              Macedonian (FYROM) Keyboard Layout
    kbdmacst.dll               6.1.7600.16385              Macedonian (FYROM) - Standard Keyboard Layout
    kbdmaori.dll               6.1.7601.17514              Maori Keyboard Layout
    kbdmlt47.dll               6.1.7600.16385              Maltese 47-key Keyboard Layout
    kbdmlt48.dll               6.1.7600.16385              Maltese 48-key Keyboard Layout
    kbdmon.dll                 6.1.7601.17514              Mongolian Keyboard Layout
    kbdmonmo.dll               6.1.7600.16385              Mongolian (Mongolian Script) Keyboard Layout
    kbdne.dll                  6.1.7600.16385              Dutch Keyboard Layout
    kbdnec.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               6.1.7600.16385              JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                6.1.7601.17514              Nepali Keyboard Layout
    kbdno.dll                  6.1.7600.16385              Norwegian Keyboard Layout
    kbdno1.dll                 6.1.7600.16385              Norwegian with Sami Keyboard Layout
    kbdnso.dll                 6.1.7600.16385              Sesotho sa Leboa Keyboard Layout
    kbdpash.dll                6.1.7600.16385              Pashto (Afghanistan) Keyboard Layout
    kbdpl.dll                  6.1.7600.16385              Polish Keyboard Layout
    kbdpl1.dll                 6.1.7600.16385              Polish Programmer's Keyboard Layout
    kbdpo.dll                  6.1.7601.17514              Portuguese Keyboard Layout
    kbdro.dll                  6.1.7600.16385              Romanian (Legacy) Keyboard Layout
    kbdropr.dll                6.1.7600.16385              Romanian (Programmers) Keyboard Layout
    kbdrost.dll                6.1.7600.16385              Romanian (Standard) Keyboard Layout
    kbdru.dll                  6.1.7600.16385              Russian Keyboard Layout
    kbdru1.dll                 6.1.7600.16385              Russia(Typewriter) Keyboard Layout
    kbdsf.dll                  6.1.7601.17514              Swiss French Keyboard Layout
    kbdsg.dll                  6.1.7601.17514              Swiss German Keyboard Layout
    kbdsl.dll                  6.1.7600.16385              Slovak Keyboard Layout
    kbdsl1.dll                 6.1.7600.16385              Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               6.1.7600.16385              Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               6.1.7600.16385              Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 6.1.7600.16385              Sinhala Keyboard Layout
    kbdsorex.dll               6.1.7600.16385              Sorbian Extended Keyboard Layout
    kbdsors1.dll               6.1.7600.16385              Sorbian Standard Keyboard Layout
    kbdsorst.dll               6.1.7600.16385              Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  6.1.7600.16385              Spanish Keyboard Layout
    kbdsw.dll                  6.1.7600.16385              Swedish Keyboard Layout
    kbdsw09.dll                6.1.7600.16385              Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                6.1.7600.16385              Syriac Standard Keyboard Layout
    kbdsyr2.dll                6.1.7600.16385              Syriac Phoenetic Keyboard Layout
    kbdtajik.dll               6.1.7601.17514              Tajik Keyboard Layout
    kbdtat.dll                 6.1.7600.16385              Tatar_Cyrillic Keyboard Layout
    kbdth0.dll                 6.1.7600.16385              Thai Kedmanee Keyboard Layout
    kbdth1.dll                 6.1.7600.16385              Thai Pattachote Keyboard Layout
    kbdth2.dll                 6.1.7600.16385              Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 6.1.7600.16385              Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtiprc.dll               6.1.7600.16385              Tibetan (PRC) Keyboard Layout
    kbdtuf.dll                 6.1.7601.17514              Turkish F Keyboard Layout
    kbdtuq.dll                 6.1.7601.17514              Turkish Q Keyboard Layout
    kbdturme.dll               6.1.7601.17514              Turkmen Keyboard Layout
    kbdughr.dll                6.1.7600.16385              Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               6.1.7601.17514              Uyghur Keyboard Layout
    kbduk.dll                  6.1.7600.16385              United Kingdom Keyboard Layout
    kbdukx.dll                 6.1.7600.16385              United Kingdom Extended Keyboard Layout
    kbdur.dll                  6.1.7600.16385              Ukrainian Keyboard Layout
    kbdur1.dll                 6.1.7600.16385              Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                6.1.7600.16385              Urdu Keyboard Layout
    kbdus.dll                  6.1.7601.17514              United States Keyboard Layout
    kbdusa.dll                 6.1.7600.16385              US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 6.1.7600.16385              Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 6.1.7600.16385              Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 6.1.7600.16385              US Multinational Keyboard Layout
    kbduzb.dll                 6.1.7600.16385              Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                6.1.7600.16385              Vietnamese Keyboard Layout
    kbdwol.dll                 6.1.7600.16385              Wolof Keyboard Layout
    kbdyak.dll                 6.1.7600.16385              Yakut - Russia Keyboard Layout
    kbdyba.dll                 6.1.7600.16385              Yoruba Keyboard Layout
    kbdycc.dll                 6.1.7600.16385              Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 6.1.7600.16385              Serbian (Latin) Keyboard Layout
    kerberos.dll               6.1.7601.17926                Kerberos
    kernel32.dll               6.1.7601.18229                Windows NT BASE API
    kernelbase.dll             6.1.7601.18229                Windows NT BASE API
    keyiso.dll                 6.1.7600.16385                 CNG
    keymgr.dll                 6.1.7600.16385                  
    korwbrkr.dll               6.1.7600.16385              korwbrkr
    ksuser.dll                 6.1.7600.16385              User CSA Library
    ktmw32.dll                 6.1.7600.16385              Windows KTM Win32 Client DLL
    l2gpstore.dll              6.1.7600.16385              Policy Storage dll
    l2nacp.dll                 6.1.7600.16385                 Onex Windows
    l2sechc.dll                6.1.7600.16385                    2
    laprxy.dll                 12.0.7600.16385             Windows Media Logagent Proxy
    licmgr10.dll               8.0.7601.17514               (DLL)    Microsoft
    linkinfo.dll               6.1.7600.16385              Windows Volume Tracking
    loadperf.dll               6.1.7600.16385                  
    localsec.dll               6.1.7601.17514               MMC "   "
    locationapi.dll            6.1.7600.16385              Microsoft Windows Location API
    loghours.dll               6.1.7600.16385               
    logoncli.dll               6.1.7601.17514              Net Logon Client DLL
    lpk.dll                    6.1.7601.18177              Language Pack
    lsmproxy.dll               6.1.7601.17514              LSM interfaces proxy Dll
    luainstall.dll             6.1.7601.17514              Lua manifest install
    lz32.dll                   6.1.7600.16385              LZ Expand/Compress API DLL
    magcore.dll                1.0.0.180                   MagCore
    magnification.dll          6.1.7600.16385               API  ()
    magpcmac.dll               1.0.0.180                   MagPCMac
    maguiengine.dll            1.0.0.180                   MagUIEngine
    maguiinter.dll             1.0.0.180                   MagUIInter
    mapi32.dll                 1.0.2536.0                    MAPI 1.0  Windows NT
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapir.dll                  11.0.5510.0                 ExOlk Intl Pluggable UI
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    mc_bc_dec_avc.dll          8.5.0.7438                  AVC/H.264 Decoder
    mcewmdrmndbootstrap.dll    1.3.2302.0                  Windows Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
    mciavi32.dll               6.1.7601.17514               MCI Video  Windows
    mcicda.dll                 6.1.7600.16385               MCI   cdaudio
    mciqtz32.dll               6.6.7601.17514               MCI DirectShow
    mciseq.dll                 6.1.7600.16385               MCI   MIDI
    mciwave.dll                6.1.7600.16385               MCI   
    mctres.dll                 6.1.7600.16385                MCT
    mdminst.dll                6.1.7600.16385               
    mediametadatahandler.dll   6.1.7601.17514              Media Metadata Handler
    mf.dll                     12.0.7601.17514               
    mf3216.dll                 6.1.7600.16385              32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               6.1.7600.16385              Media Foundation AAC Encoder
    mfc100.dll                 10.0.40219.1                MFCDLL Shared Library - Retail Version
    mfc100chs.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100cht.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100deu.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100enu.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100esn.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100fra.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100ita.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100jpn.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100kor.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100rus.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100u.dll                10.0.40219.1                MFCDLL Shared Library - Retail Version
    mfc110.dll                 11.0.60610.1                MFCDLL Shared Library - Retail Version
    mfc110chs.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110cht.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110deu.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110enu.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110esn.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110fra.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110ita.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110jpn.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110kor.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110rus.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110u.dll                11.0.60610.1                MFCDLL Shared Library - Retail Version
    mfc40.dll                  4.1.0.6151                    MFCDLL -  
    mfc40u.dll                 4.1.0.6151                    MFCDLL -  
    mfc42.dll                  6.6.8064.0                    MFCDLL -  
    mfc42rus.dll               6.0.8267.0                    MFC
    mfc42u.dll                 6.6.8064.0                    MFCDLL -  
    mfc70.dll                  7.0.9466.0                  MFCDLL Shared Library - Retail Version
    mfcm100.dll                10.0.40219.1                MFC Managed Library - Retail Version
    mfcm100u.dll               10.0.40219.1                MFC Managed Library - Retail Version
    mfcm110.dll                11.0.60610.1                MFC Managed Library - Retail Version
    mfcm110u.dll               11.0.60610.1                MFC Managed Library - Retail Version
    mfcsubs.dll                2001.12.8530.16385          COM+
    mfds.dll                   12.0.7601.17514             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                6.1.7600.16385              Media Foundation DV Decoder
    mferror.dll                12.0.7600.16385                
    mfh264enc.dll              6.1.7600.16385              Media Foundation H264 Encoder
    mfmjpegdec.dll             6.1.7600.16385              Media Foundation MJPEG Decoder
    mfplat.dll                 12.0.7600.16385             Media Foundation Platform DLL
    mfplay.dll                 12.0.7601.17514             Media Foundation Playback API DLL
    mfps.dll                   12.0.7600.16385             Media Foundation Proxy DLL
    mfreadwrite.dll            12.0.7601.17514             Media Foundation ReadWrite DLL
    mfvdsp.dll                 6.1.7600.16385              Windows Media Foundation Video DSP Components
    mfwmaaec.dll               6.1.7600.16385              Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                6.1.7600.16385              Microsoft SNMP Manager API (uses WinSNMP)
    midas.dll                  15.0.3953.35171             Embarcadero MIDAS Component Package
    midimap.dll                6.1.7600.16385              Microsoft MIDI Mapper
    migisol.dll                6.1.7601.17514              Migration System Isolation Layer
    miguiresource.dll          6.1.7600.16385               MIG wini32
    mimefilt.dll               2008.0.7601.17514            MIME
    mlang.dll                  6.1.7600.16385               DLL  
    mmcbase.dll                6.1.7600.16385                DLL MMC
    mmci.dll                   6.1.7600.16385                
    mmcico.dll                 6.1.7600.16385              Media class co-installer
    mmcndmgr.dll               6.1.7601.17514                 MMC
    mmcshext.dll               6.1.7600.16385              MMC Shell Extension DLL
    mmdevapi.dll               6.1.7601.17514              MMDevice API
    mmres.dll                  6.1.7600.16385               
    modemui.dll                6.1.7600.16385                Windows
    moricons.dll               6.1.7600.16385              Windows NT Setup Icon Resources Library
    mp3dmod.dll                6.1.7600.16385              Microsoft MP3 Decoder DMO
    mp43decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               6.1.7600.16385              Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mpr.dll                    6.1.7600.16385                   
    mprapi.dll                 6.1.7601.17514              Windows NT MP Router Administration DLL
    mprddm.dll                 6.1.7601.17514                  
    mprdim.dll                 6.1.7600.16385                
    mprmsg.dll                 6.1.7600.16385               (DLL)    
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               6.1.7601.17514              Microsoft AC-3 Encoder
    msacm32.dll                6.1.7600.16385                 Microsoft
    msadce.dll                 6.1.7601.17514              OLE DB Cursor Engine
    msadcer.dll                6.1.7600.16385              OLE DB Cursor Engine Resources
    msadcf.dll                 6.1.7601.17514              Remote Data Services Data Factory
    msadcfr.dll                6.1.7600.16385              Remote Data Services Data Factory Resources
    msadco.dll                 6.1.7601.17857              Remote Data Services Data Control
    msadcor.dll                6.1.7600.16385              Remote Data Services Data Control Resources
    msadcs.dll                 6.1.7601.17514              Remote Data Services ISAPI Library
    msadds.dll                 6.1.7600.16385              OLE DB Data Shape Provider
    msaddsr.dll                6.1.7600.16385               OLE DB Data Shape Provider Resources
    msader15.dll               6.1.7600.16385              ActiveX Data Objects Resources
    msado15.dll                6.1.7601.17857              ActiveX Data Objects
    msadomd.dll                6.1.7601.17857              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               6.1.7601.17857              Microsoft ActiveX Data Objects Recordset
    msadox.dll                 6.1.7601.17857              ActiveX Data Objects Extensions
    msadrh15.dll               6.1.7600.16385              ActiveX Data Objects Rowset Helper
    msafd.dll                  6.1.7600.16385              Microsoft Windows Sockets 2.0 Service Provider
    msasn1.dll                 6.1.7601.17514              ASN.1 Runtime APIs
    msaudite.dll               6.1.7600.16385                 
    mscandui.dll               6.1.7600.16385                MSCANDUI
    mscat32.dll                6.1.7600.16385              MSCAT32 Forwarder DLL
    mscms.dll                  6.1.7601.17514              DLL-    
    mscoree.dll                4.0.40305.0                 Microsoft .NET Runtime Execution Engine
    mscorier.dll               2.0.50727.5420               IE    Microsoft .NET
    mscories.dll               2.0.50727.5420              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               6.1.7600.16385              ODBC Code Page Translator Resources
    mscpxl32.dll               6.1.7600.16385                 ODBC
    msctf.dll                  6.1.7600.16385                MSCTF
    msctfmonitor.dll           6.1.7600.16385              MsCtfMonitor DLL
    msctfp.dll                 6.1.7600.16385              MSCTFP Server DLL
    msctfui.dll                6.1.7600.16385                MSCTFUI
    msdadc.dll                 6.1.7600.16385              OLE DB Data Conversion Stub
    msdadiag.dll               6.1.7600.16385              Built-In Diagnostics
    msdaenum.dll               6.1.7600.16385              OLE DB Root Enumerator Stub
    msdaer.dll                 6.1.7600.16385              OLE DB Error Collection Stub
    msdaipp.dll                11.0.5510.0                 Microsoft Data Access Component Internet Publishing Provider
    msdaora.dll                6.1.7600.16385              OLE DB Provider for Oracle
    msdaorar.dll               6.1.7600.16385              OLE DB Provider for Oracle Resources
    msdaosp.dll                6.1.7601.17632              OLE DB Simple Provider
    msdapml.dll                11.0.5510.0                 SharePoint Portal Server executable
    msdaprsr.dll               6.1.7600.16385                OLE DB Persistence Services
    msdaprst.dll               6.1.7600.16385              OLE DB Persistence Services
    msdaps.dll                 6.1.7600.16385              OLE DB Interface Proxies/Stubs
    msdarem.dll                6.1.7601.17514              OLE DB Remote Provider
    msdaremr.dll               6.1.7600.16385              OLE DB Remote Provider Resources
    msdart.dll                 6.1.7600.16385              OLE DB Runtime Routines
    msdasc.dll                 6.1.7600.16385              OLE DB Service Components Stub
    msdasql.dll                6.1.7601.17514              OLE DB Provider for ODBC Drivers
    msdasqlr.dll               6.1.7600.16385              OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                6.1.7600.16385              OLE DB Implementation Support Routines
    msdatt.dll                 6.1.7600.16385              OLE DB Temporary Table Services
    msdaurl.dll                6.1.7600.16385              OLE DB RootBinder Stub
    msdelta.dll                6.1.7600.16385              Microsoft Patch Engine
    msdfmap.dll                6.1.7601.17514              Data Factory Handler
    msdmeng.dll                8.0.760.0                   Microsoft Data Mining Engine
    msdmine.dll                8.0.760.0                   Microsoft OLE DB Provider for Data Mining Services
    msdmo.dll                  6.6.7601.17514              DMO Runtime
    msdrm.dll                  6.1.7601.17514                 Windows
    msdtcprx.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtcuiu.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.8530.16385               Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9756.0                  Microsoft Jet Excel Isam
    msfeeds.dll                8.0.7601.17608              Microsoft Feeds Manager
    msfeedsbs.dll              8.0.7601.17514                 ()
    msftedit.dll               5.41.21.2510                Rich Text Edit Control, v4.1
    mshtml.dll                 8.0.7601.18129                HTML Microsoft
    mshtmled.dll               8.0.7601.17514              Microsoft HTML Editing Component
    mshtmler.dll               8.0.7600.16385                  HTML (Microsoft)
    msi.dll                    5.0.7601.17807              Windows Installer
    msidcrl30.dll              6.1.7600.16385              IDCRL Dynamic Link Library
    msident.dll                6.1.7600.16385                (Microsoft)
    msidle.dll                 6.1.7600.16385              User Idle Monitor
    msidntld.dll               6.1.7600.16385                (Microsoft)
    msieftp.dll                6.1.7601.17514                Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.7601.17514              Windows installer
    msiltcfg.dll               5.0.7600.16385              Windows Installer Configuration API Stub
    msimg32.dll                6.1.7600.16385              GDIEXT Client DLL
    msimsg.dll                 5.0.7600.16385                 Windows
    msimtf.dll                 6.1.7600.16385              Active IMM Server DLL
    msisip.dll                 5.0.7600.16385              MSI Signature SIP Provider
    msjet40.dll                4.0.9756.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9756.0                  
    msjint40.dll               4.0.9756.0                       Microsoft Jet
    msjro.dll                  6.1.7601.17857              Jet and Replication Objects
    msjter40.dll               4.0.9756.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9756.0                  Microsoft Jet Expression Service
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9756.0                  Microsoft Jet Lotus 1-2-3 Isam
    msmapi32.dll               11.0.5601.0                 Extended MAPI 1.0 for Windows NT
    msmdcb80.dll               8.0.760.0                   PivotTable Service dll
    msmdgd80.dll               8.0.760.0                   Microsoft SQL Server Analysis Services driver
    msmdun80.dll               2000.80.382.0               String Function .DLL for SQL Enterprise Components
    msmpeg2adec.dll            6.1.7140.0                  Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             6.1.7601.17514               Microsoft MPEG-2
    msmpeg2vdec.dll            6.1.7140.0                  Microsoft DTV-DVD Video Decoder
    msnetobj.dll               11.0.7601.17514             DRM ActiveX Network Object
    msobjs.dll                 6.1.7600.16385                 
    msoeacct.dll               6.1.7600.16385              Microsoft Internet Account Manager
    msoert2.dll                6.1.7600.16385              Microsoft Windows Mail RT Lib
    msolap80.dll               8.0.760.0                   Microsoft OLE DB Provider for Analysis Services 8.0
    msolui80.dll               8.0.0.382                   Microsoft OLE DB provider for Analysis Services connection dialog 8.0
    msorc32r.dll               6.1.7600.16385                ODBC  Oracle
    msorcl32.dll               6.1.7601.17514              ODBC Driver for Oracle
    mspatcha.dll               6.1.7600.16385              Microsoft File Patch Application API
    mspbde40.dll               4.0.9756.0                  Microsoft Jet Paradox Isam
    msports.dll                6.1.7600.16385                 
    msprpru.dll                6.0.81.63                   msprop32.ocx
    mspst32.dll                11.0.5604.0                 Microsoft Personal Folder/Address Book Service Provider
    msrating.dll               8.0.7601.17514                   
    msrd2x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrdc.dll                  6.1.7600.16385              Remote Differential Compression COM server
    msrdo20.dll                6.0.88.62                   MSRDO20 rdoEngine control
    msrdpwebaccess.dll         6.1.7600.16385              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9756.0                  Microsoft Replication Library
    msrle32.dll                6.1.7601.17514              Microsoft RLE Compressor
    msscntrs.dll               7.0.7601.17610              msscntrs.dll
    msscp.dll                  11.0.7601.17514             Windows Media Secure Content Provider
    mssha.dll                  6.1.7600.16385                  Windows
    msshavmsg.dll              6.1.7600.16385                     Windows
    msshooks.dll               7.0.7600.16385              MSSHooks.dll
    mssign32.dll               6.1.7600.16385               API  
    mssip32.dll                6.1.7600.16385              MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.7600.16385              mssitlb
    mssph.dll                  7.0.7601.17610                 Microsoft
    mssphtb.dll                7.0.7601.17610              Outlook MSSearch Connector
    mssprxy.dll                7.0.7600.16385              Microsoft Search Proxy
    mssrch.dll                 7.0.7601.17610              mssrch.dll
    msstdfmt.dll               6.0.84.50                   Microsoft Standard Data Formating Object DLL
    msstkprp.dll               6.0.81.69                   msprop32.ocx
    mssvp.dll                  7.0.7601.17610               Vista MSSearch
    msswch.dll                 6.1.7600.16385              msswch
    mstask.dll                 6.1.7601.17514                 
    mstext40.dll               4.0.9756.0                  Microsoft Jet Text Isam
    mstime.dll                 8.0.7601.17514              Microsoft (R) Timed Interactive Multimedia Extensions to HTML
    mstscax.dll                6.1.7601.18079              ActiveX-    
    msutb.dll                  6.1.7601.17514               (DLL)  MSUTB
    msv1_0.dll                 6.1.7601.17514              Microsoft Authentication Package v1.0
    msvbvm60.dll               6.0.98.15                   Visual Basic Virtual Machine
    msvcirt.dll                7.0.7600.16385              Windows NT IOStreams DLL
    msvcp100.dll               10.0.40219.1                Microsoft C Runtime Library
    msvcp110.dll               11.0.51106.1                Microsoft C Runtime Library
    msvcp110_clr0400.dll       12.0.51209.34209            Microsoft .NET Framework
    msvcp120_clr0400.dll       12.0.51209.34209            Microsoft C Runtime Library
    msvcp60.dll                7.0.7600.16385              Windows NT C++ Runtime Library DLL
    msvcp70.dll                7.0.9466.0                  Microsoft C++ Runtime Library
    msvcp71.dll                7.10.3077.0                 Microsoft C++ Runtime Library
    msvcr100.dll               10.0.40219.1                Microsoft C Runtime Library
    msvcr100_clr0400.dll       12.0.51209.34209            Microsoft .NET Framework
    msvcr110.dll               11.0.51106.1                Microsoft C Runtime Library
    msvcr110_clr0400.dll       12.0.51209.34209            Microsoft .NET Framework
    msvcr120_clr0400.dll       12.0.51209.34209            Microsoft C Runtime Library
    msvcr70.dll                7.0.9466.0                  Microsoft C Runtime Library
    msvcr71.dll                7.10.3052.4                 Microsoft C Runtime Library
    msvcrt.dll                 7.0.7601.17744              Windows NT CRT DLL
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               6.1.7600.16385              VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                6.1.7601.17514               Microsoft Video  Windows
    msvidc32.dll               6.1.7601.17514                Microsoft Video 1
    msvidctl.dll               6.5.7601.17514               ActiveX  
    mswdat10.dll               4.0.9756.0                  Microsoft Jet Sort Tables
    mswmdm.dll                 12.0.7600.16385               Windows Media Device Manager
    mswsock.dll                6.1.7601.18254                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9756.0                    Microsoft Jet
    msxactps.dll               6.1.7600.16385              OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9756.0                  Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.7601.17988            MSXML 3.0 SP11
    msxml3a.dll                8.20.8730.1                 XML Resources
    msxml3r.dll                8.110.7601.16665            XML Resources
    msxml4.dll                 4.30.2100.0                 MSXML 4.0 SP3
    msxml4r.dll                4.30.2100.0                 MSXML 4.0 SP3 Resources
    msxml6.dll                 6.30.7601.17988             MSXML 6.0 SP3
    msxml6r.dll                6.30.7600.16385             XML Resources
    msyuv.dll                  6.1.7601.17514              Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.8531.17514          Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.8530.16385          COM+
    mtxex.dll                  2001.12.8530.16385          COM+
    mtxlegih.dll               2001.12.8530.16385          COM+
    mtxoci.dll                 2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           6.1.7601.17514              MUI Callback for font registry settings
    mycomput.dll               6.1.7600.16385               
    mydocs.dll                 6.1.7601.17514                 " "
    napcrypt.dll               6.1.7601.17514              NAP Cryptographic API helper
    napdsnap.dll               6.1.7601.17514               GPEdit    
    naphlpr.dll                6.1.7601.17514              NAP client config API helper
    napinsp.dll                6.1.7600.16385                    
    napipsec.dll               6.1.7600.16385                      IPSec
    napmontr.dll               6.1.7600.16385                NAP  Netsh
    nativehooks.dll            6.1.7600.16385              Microsoft Narrator Native hook handler
    naturallanguage6.dll       6.1.7601.17514              Natural Language Development Platform 6
    ncdprop.dll                6.1.7600.16385                 
    nci.dll                    6.1.7601.17514              CoInstaller: NET
    ncobjapi.dll               6.1.7600.16385              Microsoft Windows Operating System
    ncrypt.dll                 6.1.7601.18007                (Windows)
    ncryptui.dll               6.1.7601.17514               UI     Windows
    ncsi.dll                   6.1.7601.17964                 
    nddeapi.dll                6.1.7600.16385              Network DDE Share Management APIs
    ndfapi.dll                 6.1.7600.16385              API    
    ndfetw.dll                 6.1.7600.16385              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         6.1.7600.16385              Network Diagnostic Framework HC Discovery API
    ndiscapcfg.dll             6.1.7600.16385              NdisCap Notify Object
    ndishc.dll                 6.1.7600.16385                NDIS
    ndproxystub.dll            6.1.7600.16385              Network Diagnostic Engine Proxy/Stub
    negoexts.dll               6.1.7600.16385              NegoExtender Security Package
    netapi32.dll               6.1.7601.17887              Net Win32 API DLL
    netbios.dll                6.1.7600.16385              NetBIOS Interface Library
    netcenter.dll              6.1.7601.17514                 -  
    netcfgx.dll                6.1.7601.17514                
    netcorehc.dll              6.1.7601.17964                   
    netdiagfx.dll              6.1.7601.17514                
    netevent.dll               6.1.7601.17964                
    netfxperf.dll              4.0.40305.0                 Extensible Performance Counter Shim
    neth.dll                   6.1.7600.16385                 
    netid.dll                  6.1.7601.17514                  
    netiohlp.dll               6.1.7601.17514               DLL   Netio
    netjoin.dll                6.1.7601.17514              Domain Join DLL
    netlogon.dll               6.1.7601.17514                 Net Logon
    netmsg.dll                 6.1.7600.16385                
    netplwiz.dll               6.1.7601.17514                   
    netprof.dll                6.1.7600.16385                 
    netprofm.dll               6.1.7600.16385                
    netshell.dll               6.1.7601.17514                
    netutils.dll               6.1.7601.17514              Net Win32 API Helpers DLL
    networkexplorer.dll        6.1.7601.17514               
    networkitemfactory.dll     6.1.7600.16385                
    networkmap.dll             6.1.7601.17514               
    newdev.dll                 6.0.5054.0                    
    nlaapi.dll                 6.1.7601.17761              Network Location Awareness 2
    nlhtml.dll                 2008.0.7600.16385            HTML
    nlmgp.dll                  6.1.7600.16385                 
    nlmsprep.dll               6.1.7600.16385              Network List Manager Sysprep Module
    nlsbres.dll                6.1.7601.17514              NLSBuild resource DLL
    nlsdata0000.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0001.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0002.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0003.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0007.dll            6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlsdata0009.dll            6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlsdata000a.dll            6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlsdata000c.dll            6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlsdata000d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata000f.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0010.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0011.dll            6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlsdata0013.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0018.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0019.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0020.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0021.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0022.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0024.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0026.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0027.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata002a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0039.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata003e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0045.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0046.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0047.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0049.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004c.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0414.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0416.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0816.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata081a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0c1a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdl.dll                  6.1.7600.16385              Nls Downlevel DLL
    nlslexicons0001.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0002.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0003.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0007.dll        6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlslexicons0009.dll        6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlslexicons000a.dll        6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlslexicons000c.dll        6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlslexicons000d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons000f.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0010.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0011.dll        6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlslexicons0013.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0018.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0019.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0020.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0021.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0022.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0024.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0026.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0027.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons002a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0039.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons003e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0045.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0046.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0047.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0049.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004c.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0414.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0416.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0816.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons081a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0c1a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsmodels0011.dll          6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    normaliz.dll               6.1.7600.16385              Unicode Normalization DLL
    npmproxy.dll               6.1.7600.16385              Network List Manager Proxy
    npptools.dll               5.1.2600.1106                  NPP
    nshhttp.dll                6.1.7600.16385               DLL netsh  HTTP
    nshipsec.dll               6.1.7601.17514               DLL  IPSec  Net
    nshwfp.dll                 6.1.7601.17514                  Windows  Netsh
    nsi.dll                    6.1.7600.16385              NSI User-mode interface DLL
    ntdll.dll                  6.1.7601.18247                NT
    ntdsapi.dll                6.1.7600.16385              Active Directory Domain Services API
    ntlanman.dll               6.1.7601.17514              Microsoft LAN Manager
    ntlanui2.dll               6.1.7600.16385                  
    ntmarta.dll                6.1.7600.16385               Windows NT MARTA
    ntprint.dll                6.1.7601.17514                  
    ntshrui.dll                6.1.7601.17755               ,    
    ntvdm64.dll                6.1.7601.18247              16-   NT64
    nvapi.dll                  9.18.13.5286                NVIDIA NVAPI Library, Version 352.86 
    nvcompiler.dll                                         
    nvcuda.dll                 8.17.13.5286                NVIDIA CUDA Driver, Version 352.86 
    nvcuvid.dll                7.17.13.5286                NVIDIA CUDA Video Decode API, Version 352.86 
    nvd3dum.dll                9.18.13.5286                NVIDIA WDDM D3D Driver, Version 352.86 
    nvencodeapi.dll            6.14.13.5286                NVIDIA Video Encoder API, Version 3.0 
    nvfbc.dll                  6.14.13.5286                NVIDIA Frame Buffer Capture Library, Version 
    nvifr.dll                  6.14.13.5286                NVIDIA In-band Frame Rendering Library, Version 
    nvifropengl.dll            9.18.13.5286                NVIDIA OpenGL In-band Frame Readback Library, Version 
    nvinit.dll                 9.18.13.5286                NVIDIA shim initialization dll, Version 352.86 
    nvoglshim32.dll            9.18.13.5286                NVIDIA OpenGL Shim Driver, Version 352.86 
    nvoglv32.dll               9.18.13.5286                NVIDIA Compatible OpenGL ICD
    nvopencl.dll               8.17.13.5286                NVIDIA CUDA 7.5.8 OpenCL 1.1 Driver, Version 352.86 
    nvumdshim.dll              9.18.13.5286                NVIDIA D3D Shim Driver, Version 352.86 
    nvwgf2um.dll               9.18.13.5286                NVIDIA D3D10 Driver, Version 352.86 
    objsel.dll                 6.1.7600.16385                
    occache.dll                8.0.7601.17514                  
    ocsetapi.dll               6.1.7601.17514              Windows Optional Component Setup API
    odbc32.dll                 6.1.7601.17514              ODBC Driver Manager
    odbc32gt.dll               6.1.7600.16385              ODBC Driver Generic Thunk
    odbcbcp.dll                6.1.7600.16385              BCP for ODBC
    odbcconf.dll               6.1.7601.17514              ODBC Driver Configuration Program
    odbccp32.dll               6.1.7601.17632              ODBC Installer
    odbccr32.dll               6.1.7601.17632              ODBC Cursor Library
    odbccu32.dll               6.1.7601.17632              ODBC Cursor Library
    odbcint.dll                6.1.7600.16385              ODBC Resources
    odbcji32.dll               6.1.7600.16385              Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               6.1.7601.17632              Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               6.1.7601.17632              ODBC Driver Manager Trace
    oddbse32.dll               6.1.7600.16385              ODBC (3.0) driver for DBase
    odexl32.dll                6.1.7600.16385              ODBC (3.0) driver for Excel
    odfox32.dll                6.1.7600.16385              ODBC (3.0) driver for FoxPro
    odpdx32.dll                6.1.7600.16385              ODBC (3.0) driver for Paradox
    odtext32.dll               6.1.7600.16385              ODBC (3.0) driver for text files
    offfilt.dll                2008.0.7600.16385            OFFICE
    ogldrv.dll                 6.1.7600.16385              MSOGL
    ole2.dll                   2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    ole2disp.dll               2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole2nls.dll                2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole32.dll                  6.1.7601.17514              Microsoft OLE   Windows
    oleacc.dll                 7.0.0.0                     Active Accessibility Core Component
    oleacchooks.dll            7.0.0.0                     Active Accessibility Event Hooks Library
    oleaccrc.dll               7.0.0.0                     Active Accessibility Resource DLL
    oleaut32.dll               6.1.7601.17676              
    olecli32.dll               6.1.7600.16385                OLE
    oledb32.dll                6.1.7601.17514              OLE DB Core Services
    oledb32r.dll               6.1.7600.16385                 OLE DB
    oledlg.dll                 6.1.7600.16385                 OLE
    oleprn.dll                 6.1.7600.16385              Oleprn DLL
    olepro32.dll               6.1.7601.17514              
    oleres.dll                 6.1.7600.16385                OLE
    olesvr32.dll               6.1.7600.16385              Object Linking and Embedding Server Library
    olethk32.dll               6.1.7601.17514              Microsoft OLE for Windows
    onex.dll                   6.1.7601.17514                IEEE 802.1X
    onexui.dll                 6.1.7601.17514                 IEEE 802.1X
    onlineidcpl.dll            6.1.7601.17514                -  
    oobefldr.dll               6.1.7601.17514                
    opcservices.dll            6.1.7601.17514              Native Code OPC Services Library
    opencl.dll                 1.2.11.0                    OpenCL Client DLL
    opengl32.dll               6.1.7600.16385              OpenGL Client DLL
    osbaseln.dll               6.1.7600.16385              Service Reporting API
    osuninst.dll               6.1.7600.16385              Uninstall Interface
    outex.dll                  11.0.5525.0                 Outlook Exchange User Interface
    p2p.dll                    6.1.7600.16385                
    p2pcollab.dll              6.1.7600.16385                  
    p2pgraph.dll               6.1.7600.16385              Peer-to-Peer Graphing
    p2pnetsh.dll               6.1.7600.16385                 NetSh
    packager.dll               6.1.7601.17727               2
    panmap.dll                 6.1.7600.16385              PANOSE(tm) Font Mapper
    pautoenr.dll               6.1.7600.16385                
    pcaui.dll                  6.1.7600.16385                  
    pcwum.dll                  6.1.7600.16385              Performance Counters for Windows Native DLL
    pdh.dll                    6.1.7601.17514                  Windows
    pdhui.dll                  6.1.7601.17514                
    pdvcodec.dll               2.64.1119.1600              DV Video for Windows Driver
    peerdist.dll               6.1.7600.16385                BranchCache
    peerdistsh.dll             6.1.7600.16385                BranchCache Netshell
    perfcentercpl.dll          6.1.7601.17514               
    perfctrs.dll               6.1.7600.16385               
    perfdisk.dll               6.1.7600.16385                  Windows
    perfnet.dll                6.1.7600.16385                   Windows
    perfos.dll                 6.1.7600.16385                  Windows
    perfproc.dll               6.1.7600.16385                   Windows
    perfts.dll                 6.1.7601.17514              Windows Remote Desktop Services Performance Objects
    photometadatahandler.dll   6.1.7600.16385              Photo Metadata Handler
    photowiz.dll               6.1.7601.17514                
    pid.dll                    6.1.7600.16385              Microsoft PID
    pidgenx.dll                6.1.7600.16385              Pid Generation
    pifmgr.dll                 6.1.7601.17514              Windows NT PIF Manager Icon Resources Library
    pku2u.dll                  6.1.7600.16385              Pku2u Security Package
    pla.dll                    6.1.7601.17514                 
    playsndsrv.dll             6.1.7600.16385               PlaySound
    pmcsnap.dll                6.1.7600.16385              pmcsnap dll
    pncrt.dll                  6.0.0.0                     Real Networks C/C++ Runtime Library
    pndx5016.dll               5.0.0.0                     16 bit DirectX helper DLL
    pndx5032.dll               5.0.0.0                     32 bit DirectX helper DLL
    pngfilt.dll                8.0.7600.16385              IE PNG plugin image decoder
    pnidui.dll                 6.1.7601.17514                
    pnpsetup.dll               6.1.7600.16385              Pnp installer for CMI
    pnrpnsp.dll                6.1.7600.16385                 PNRP
    polstore.dll               6.1.7600.16385              Policy Storage dll
    portabledeviceapi.dll      6.1.7601.17514               API    Windows
    portabledeviceclassextension.dll  6.1.7600.16385              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  6.1.7600.16385              Portable Device Connection API Components
    portabledevicestatus.dll   6.1.7601.17514                  Microsoft Windows
    portabledevicesyncprovider.dll  6.1.7601.17514                 Microsoft Windows
    portabledevicetypes.dll    6.1.7600.16385              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  6.1.7600.16385              PortableDevice WIA Compatibility Driver
    portabledevicewmdrm.dll    6.1.7600.16385              Windows Portable Device WMDRM Component
    pots.dll                   6.1.7600.16385               
    powercpl.dll               6.1.7601.17514                
    powrprof.dll               6.1.7600.16385              DLL     
    ppcsnap.dll                6.1.7600.16385              ppcsnap DLL
    presentationcffrasterizernative_v0300.dll  3.0.6920.5459               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  4.0.40305.0                 Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.4902               PresentationNative_v0300.dll
    prflbmsg.dll               6.1.7600.16385                  
    printui.dll                6.1.7601.17514                 
    prncache.dll               6.1.7601.17514              Print UI Cache
    prnfldr.dll                6.1.7601.17514              prnfldr dll
    prnntfy.dll                6.1.7600.16385              prnntfy DLL
    prntvpt.dll                6.1.7601.17514              Print Ticket Services Module
    profapi.dll                6.1.7600.16385              User Profile Basic API
    propsys.dll                7.0.7601.17514                 (Microsoft)
    provsvc.dll                6.1.7601.17514                Windows
    provthrd.dll               6.1.7600.16385              WMI Provider Thread & Log Library
    psapi.dll                  6.1.7600.16385              Process Status Helper
    psbase.dll                 6.1.7600.16385                
    pshed.dll                  6.1.7600.16385                ,   
    psisdecd.dll               6.6.7601.17669              Microsoft SI/PSI parser for MPEG2 based networks.
    pstorec.dll                6.1.7600.16385              Protected Storage COM interfaces
    pstorsvc.dll               6.1.7600.16385              Protected storage server
    pstprx32.dll               11.0.5525.0                 Proxy Store Provider
    pthreadgc2.dll             2.8.0.0                     POSIX Threads for Windows32 Library
    puiapi.dll                 6.1.7600.16385               DLL puiapi
    puiobj.dll                 6.1.7601.17514               DLL  PrintUI
    pwrshplugin.dll            6.1.7600.16385              pwrshplugin.dll
    qagent.dll                 6.1.7601.17514                
    qasf.dll                   12.0.7601.17514             DirectShow ASF Support
    qcap.dll                   6.6.7601.17514                DirecxX DirectShow.
    qcliprov.dll               6.1.7601.17514               WMI   
    qdv.dll                    6.6.7601.17514                DirecxX DirectShow.
    qdvd.dll                   6.6.7601.17713              DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.6.7601.18175               DirectShow
    qedwipes.dll               6.6.7600.16385              DirectShow Editing SMPTE Wipes
    qmgrprxy.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    qshvhost.dll               6.1.7601.17514                SHV
    qsvrmgmt.dll               6.1.7601.17514                
    quartz.dll                 6.6.7601.17713                DirecxX DirectShow.
    query.dll                  6.1.7601.17514                  
    qutil.dll                  6.1.7601.17514                
    qwave.dll                  6.1.7600.16385              Windows NT
    racengn.dll                6.1.7601.17514                  
    racpldlg.dll               6.1.7600.16385                 
    radardt.dll                6.1.7600.16385                   Windows
    radarrs.dll                6.1.7600.16385                   Microsoft Windows
    rasadhlp.dll               6.1.7600.16385              Remote Access AutoDial Helper
    rasapi32.dll               6.1.7600.16385              Remote Access API
    rascfg.dll                 6.1.7600.16385                RAS
    raschap.dll                6.1.7601.17514                 PPP CHAP
    rasctrs.dll                6.1.7600.16385                     Windows NT
    rasdiag.dll                6.1.7600.16385                  RAS
    rasdlg.dll                 6.1.7600.16385              API     
    rasgcw.dll                 6.1.7600.16385                RAS
    rasman.dll                 6.1.7600.16385              Remote Access Connection Manager
    rasmm.dll                  6.1.7600.16385                RAS
    rasmontr.dll               6.1.7600.16385                RAS
    rasmxs.dll                 6.1.7600.16385              Remote Access Device DLL for modems, PADs and switches
    rasplap.dll                6.1.7600.16385                 RAS PLAP
    rasppp.dll                 6.1.7601.17514              Remote Access PPP
    rasser.dll                 6.1.7600.16385              Remote Access Media DLL for COM ports
    rastapi.dll                6.1.7601.17514              Remote Access TAPI Compliance Layer
    rastls.dll                 6.1.7601.17514                 PPP EAP-TLS
    rdocurs.dll                6.0.88.4                    Microsoft RDO Client Cursor DLL
    rdpcore.dll                6.1.7601.17779              RDP Core DLL
    rdpd3d.dll                 6.1.7601.17514              RDP Direct3D Remoting DLL
    rdpencom.dll               6.1.7601.17514              RDPSRAPI COM Objects
    rdpendp.dll                6.1.7601.17514                 RDP
    rdprefdrvapi.dll           6.1.7601.17514              Reflector Driver API
    rdvgumd32.dll              6.1.7601.17514                 ()
    reagent.dll                6.1.7601.17514               DLL   Microsoft Windows
    redemption.dll             4.8.0.1184                  Outlook Redemption COM library
    regapi.dll                 6.1.7601.17514              Registry Configuration APIs
    regctrl.dll                6.1.7600.16385              RegCtrl
    remotepg.dll               6.1.7601.17514              CPL-  
    resampledmo.dll            6.1.7600.16385              Windows Media Resampler
    resutils.dll               6.1.7601.17514              Microsoft Cluster Resource Utility DLL
    rgb9rast.dll               6.1.7600.16385              Microsoft Windows Operating System
    riched20.dll               5.31.23.1230                Rich Text Edit Control, v3.1
    riched32.dll               6.1.7601.17514              Wrapper Dll for Richedit 1.0
    rmoc3260.dll               6.0.10.72                   Real Player(tm) ActiveX Control
    rnr20.dll                  6.1.7600.16385              Windows Socket2 NameSpace DLL
    rpcdiag.dll                6.1.7600.16385              RPC Diagnostics
    rpchttp.dll                6.1.7601.17514              RPC HTTP DLL
    rpcndfp.dll                1.0.0.1                        RPC NDF
    rpcns4.dll                 6.1.7600.16385                    (RPC)
    rpcnsh.dll                 6.1.7600.16385                RPC Netshell
    rpcrt4.dll                 6.1.7601.18205                 
    rpcrtremote.dll            6.1.7601.17514              Remote RPC Extension
    rsaenh.dll                 6.1.7600.16385              Microsoft Enhanced Cryptographic Provider
    rshx32.dll                 6.1.7600.16385                
    rstrtmgr.dll               6.1.7600.16385               
    rtffilt.dll                2008.0.7600.16385            RTF
    rtm.dll                    6.1.7600.16385                
    rtutils.dll                6.1.7601.17514              Routing Utilities
    samcli.dll                 6.1.7601.17514              Security Accounts Manager Client DLL
    samlib.dll                 6.1.7600.16385              SAM Library DLL
    sampleres.dll              6.1.7600.16385               (Microsoft)
    sas.dll                    6.1.7600.16385              WinLogon Software SAS Library
    sbe.dll                    6.6.7601.17528              DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.7600.16385             Stream Buffer IO DLL
    sberes.dll                 6.6.7600.16385                  DirectShow.
    scansetting.dll            6.1.7601.17514                    Microsoft Windows(TM)
    scarddlg.dll               6.1.7600.16385              SCardDlg -   -
    scecli.dll                 6.1.7601.17514                 
    scesrv.dll                 6.1.7601.17514                
    schannel.dll               6.1.7601.17856              TLS / SSL Security Provider
    schedcli.dll               6.1.7601.17514              Scheduler Service Client DLL
    scksp.dll                  6.1.7600.16385              Microsoft Smart Card Key Storage Provider
    scnpst32.dll               11.0.5604.0                 Microsoft Personal Folder Recovery for ANSI Stores
    scnpst64.dll               11.0.5604.0                 Microsoft Personal Folder Recovery for UNICODE Stores
    scp32.dll                  2.0.330.0                   Code Page Translation Library
    scripto.dll                6.6.7600.16385              Microsoft ScriptO
    scrobj.dll                 5.8.7600.16385              Windows  Script Component Runtime
    scrptadm.dll               6.1.7601.17514                
    scrptxtn.dll               5.5.1960.0                  Microsoft Exchange Server Scripting
    scrrun.dll                 5.8.7600.16385              Microsoft  Script Runtime
    sdiageng.dll               6.1.7600.16385                 
    sdiagprv.dll               6.1.7600.16385              API    Windows
    sdohlp.dll                 6.1.7600.16385                 SDO NPS
    searchfolder.dll           6.1.7601.17514              SearchFolder
    sechost.dll                6.1.7600.16385              Host for SCM/SDDL/LSA Lookup APIs
    secproc.dll                6.1.7601.17514              Windows Rights Management Desktop Security Processor
    secproc_isv.dll            6.1.7601.17514              Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            6.1.7601.17514              Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        6.1.7601.17514              Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                6.1.7601.17856              Security Support Provider Interface
    security.dll               6.1.7600.16385              Security Support Provider Interface
    sendmail.dll               6.1.7600.16385               
    sens.dll                   6.1.7600.16385                   (SENS)
    sensapi.dll                6.1.7600.16385              SENS Connectivity API DLL
    sensorsapi.dll             6.1.7600.16385              Sensor API
    sensorscpl.dll             6.1.7601.17514                "    "
    serialui.dll               6.1.7600.16385                
    serwvdrv.dll               6.1.7600.16385                Unimodem
    sessenv.dll                6.1.7601.17514                   
    setupapi.dll               6.1.7601.17514              Windows Setup API
    setupcln.dll               6.1.7601.17514                
    sfc.dll                    6.1.7600.16385              Windows File Protection
    sfc_os.dll                 6.1.7600.16385              Windows File Protection
    sfcom.dll                  3.0.0.11                    SFCOM.DLL
    shacct.dll                 6.1.7601.17514              Shell Accounts Classes
    shdocvw.dll                6.1.7601.18222                    
    shell32.dll                6.1.7601.18222                 Windows
    shellstyle.dll             6.1.7600.16385              Windows Shell Style Resource Dll
    shfolder.dll               6.1.7600.16385              Shell Folder Service
    shgina.dll                 6.1.7601.17514              Windows Shell User Logon
    shimeng.dll                6.1.7600.16385              Shim Engine DLL
    shimgvw.dll                6.1.7601.17514               
    shlwapi.dll                6.1.7601.17514                 
    shpafact.dll               6.1.7600.16385              Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                6.1.7601.17514              Shell setup helper
    shsvcs.dll                 6.1.7601.17514               DLL   Windows
    shunimpl.dll               6.1.7601.17514              Windows Shell Obsolete APIs
    shwebsvc.dll               6.1.7601.17514              -  Windows
    signdrv.dll                6.1.7600.16385              WMI provider for Signed Drivers
    sisbkup.dll                6.1.7601.17514              Single-Instance Store Backup Support Functions
    slc.dll                    6.1.7600.16385              Software Licensing Client DLL
    slcext.dll                 6.1.7600.16385              Software Licensing Client Extension Dll
    slwga.dll                  6.1.7601.17514              Software Licensing WGA API
    smartcardcredentialprovider.dll  6.1.7601.17514                 - Windows
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    sndvolsso.dll              6.1.7601.17514               SCA 
    snmpapi.dll                6.1.7600.16385              SNMP Utility Library
    softkbd.dll                6.1.7600.16385                  
    softpub.dll                6.1.7600.16385              Softpub Forwarder DLL
    sortserver2003compat.dll   6.1.7600.16385              Sort Version Server 2003
    sortwindows6compat.dll     6.1.7600.16385              Sort Version Windows 6.0
    spbcd.dll                  6.1.7601.17514              BCD Sysprep Plugin
    spfileq.dll                6.1.7600.16385              Windows SPFILEQ
    spinf.dll                  6.1.7600.16385              Windows SPINF
    spnet.dll                  6.1.7600.16385              Net Sysprep Plugin
    spopk.dll                  6.1.7601.17514              OPK Sysprep Plugin
    spp.dll                    6.1.7601.17514                  Microsoft Windows
    sppc.dll                   6.1.7601.17514              Software Licensing Client DLL
    sppcc.dll                  6.1.7600.16385                  
    sppcext.dll                6.1.7600.16385              Software Protection Platform Client Extension Dll
    sppcomapi.dll              6.1.7601.17514                 
    sppcommdlg.dll             6.1.7600.16385              API     
    sppinst.dll                6.1.7601.17514              SPP CMI Installer Plug-in DLL
    sppwmi.dll                 6.1.7600.16385              Software Protection Platform WMI provider
    spwinsat.dll               6.1.7600.16385              WinSAT Sysprep Plugin
    spwizeng.dll               6.1.7601.17514              Setup Wizard Framework
    spwizimg.dll               6.1.7600.16385              Setup Wizard Framework Resources
    spwizres.dll               6.1.7601.17514                 
    spwmp.dll                  6.1.7601.17514              Windows Media Player System Preparation DLL
    sqlceoledb30.dll           3.0.7600.0                  Microsoft SQL Mobile
    sqlceqp30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqlcese30.dll              3.0.7601.0                  Microsoft SQL Mobile
    sqloledb.dll               6.1.7601.17514              OLE DB Provider for SQL Server
    sqlsrv32.dll               6.1.7601.17514              SQL Server ODBC Driver
    sqlunirl.dll               2000.80.728.0               String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 1999.10.20.0                Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 1999.10.20.0                Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                6.1.7600.16385              XML extensions for SQL Server
    sqmapi.dll                 6.1.7601.17514              SQM Client
    srchadmin.dll              7.0.7601.17514               
    srclient.dll               6.1.7601.17836              Microsoft Windows System Restore Client Library
    srhelper.dll               6.1.7600.16385              Microsoft Windows driver and windows update enumeration library
    srpuxnativesnapin.dll      6.1.7600.16385                     
    srvcli.dll                 6.1.7601.17514              Server Service Client DLL
    sscore.dll                 6.1.7601.17514               DLL-  
    ssdpapi.dll                6.1.7600.16385              SSDP Client API DLL
    sspicli.dll                6.1.7601.17856              Security Support Provider Interface
    ssshim.dll                 6.1.7600.16385              Windows Componentization Platform Servicing API
    stclient.dll               2001.12.8530.16385          COM+ Configuration Catalog Client
    sti.dll                    6.1.7600.16385                   
    stobject.dll               6.1.7601.17514                 Systray
    storage.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    storagecontexthandler.dll  6.1.7600.16385                   
    storprop.dll               6.1.7600.16385                  
    structuredquery.dll        7.0.7601.17514              Structured Query
    sud.dll                    6.1.7601.17514                SUD
    sxproxy.dll                6.1.7600.16385                  Microsoft Windows
    sxs.dll                    6.1.7601.17514              Fusion 2.5
    sxshared.dll               6.1.7600.16385              Microsoft Windows SX Shared Library
    sxsstore.dll               6.1.7600.16385              Sxs Store DLL
    synccenter.dll             6.1.7601.17514                
    synceng.dll                6.1.7601.17959              Windows Briefcase Engine
    synchostps.dll             6.1.7600.16385              Proxystub for sync host
    syncinfrastructure.dll     6.1.7600.16385                Microsoft Windows.
    syncinfrastructureps.dll   6.1.7600.16385              Microsoft Windows sync infrastructure proxy stub.
    syncreg.dll                2007.94.7600.16385          Microsoft Synchronization Framework Registration
    syncui.dll                 6.1.7601.17514               Windows
    syssetup.dll               6.1.7601.17514              Windows NT System Setup
    systemcpl.dll              6.1.7601.17514              CPL 
    t2embed.dll                6.1.7601.17514              Microsoft T2Embed Font Embedding
    tapi3.dll                  6.1.7600.16385              Microsoft TAPI3
    tapi32.dll                 6.1.7600.16385               API  Microsoft Windows
    tapimigplugin.dll          6.1.7600.16385              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               6.1.7600.16385              Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                6.1.7601.17514                 Microsoft Windows
    tapisysprep.dll            6.1.7600.16385              Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 6.1.7600.16385               DLL   Microsoft Windows
    taskcomp.dll               6.1.7601.17514                  
    taskschd.dll               6.1.7601.17514              Task Scheduler COM API
    taskschdps.dll             6.1.7600.16385              Task Scheduler Interfaces Proxy
    tbs.dll                    6.1.7600.16385              TBS
    tcpipcfg.dll               6.1.7601.17514                
    tcpmonui.dll               6.1.7600.16385                  TCP/IP
    tdh.dll                    6.1.7601.18247                 
    termmgr.dll                6.1.7601.17514              Microsoft TAPI3 Terminal Manager
    thawbrkr.dll               6.1.7600.16385              Thai Word Breaker
    themecpl.dll               6.1.7601.17514              CPL 
    themeui.dll                6.1.7601.17514              API   Windows
    thumbcache.dll             6.1.7601.17514                
    timedatemuicallback.dll    6.1.7600.16385              Time Date Control UI Language Change plugin
    tlscsp.dll                 6.1.7601.17514              Microsoft Remote Desktop Services Cryptographic Utility
    tpmcompc.dll               6.1.7600.16385                
    tquery.dll                 7.0.7601.17610              tquery.dll
    traffic.dll                6.1.7600.16385              Microsoft Traffic Control 1.0 DLL
    trapi.dll                  6.1.7601.17514              Microsoft Narrator Text Renderer
    tsbyuv.dll                 6.1.7601.17514              Toshiba Video Codec
    tsccvid.dll                3.0.0.0                     TechSmith Screen Capture Codec
    tsccvid64.dll              3.0.0.0                     TechSmith Screen Capture Codec
    tschannel.dll              6.1.7600.16385              Task Scheduler Proxy
    tsgqec.dll                 6.1.7601.18079                      
    tsmf.dll                   6.1.7601.17514                MF    
    tspkg.dll                  6.1.7601.17514              Web Service Security Package
    tsworkspace.dll            6.1.7601.17514                      RemoteApp
    tvratings.dll              6.6.7600.16385              Module for managing TV ratings
    twext.dll                  6.1.7601.17514              :  
    txflog.dll                 2001.12.8530.16385          COM+
    txfw32.dll                 6.1.7600.16385              TxF Win32 DLL
    typelib.dll                2.10.3029.1                 OLE 2.1 16/32 Interoperability Library
    tzres.dll                  6.1.7601.18217               DLL   
    ubpm.dll                   6.1.7600.16385               DLL    
    ucmhc.dll                  6.1.7600.16385                 UCM
    udhisapi.dll               6.1.7600.16385              UPnP Device Host ISAPI Extension
    uexfat.dll                 6.1.7600.16385              eXfat Utility DLL
    ufat.dll                   6.1.7600.16385              FAT Utility DLL
    uianimation.dll            6.1.7600.16385              Windows Animation Manager
    uiautomationcore.dll       7.0.0.0                        Microsoft UI
    uicom.dll                  6.1.7600.16385              Add/Remove Modems
    uiribbon.dll               6.1.7601.17514                Windows
    uiribbonres.dll            6.1.7601.17514              Windows Ribbon Framework Resources
    ulib.dll                   6.1.7600.16385              DLL   
    umdmxfrm.dll               6.1.7600.16385              Unimodem Tranform Module
    unimdmat.dll               6.1.7601.17514              - AT   Unimodem
    uniplat.dll                6.1.7600.16385              Unimodem AT Mini Driver Platform Driver for Windows NT
    unrar.dll                  5.1.100.1066                
    untfs.dll                  6.1.7601.17514              NTFS Utility DLL
    upnp.dll                   6.1.7601.17514              API   UPnP
    upnphost.dll               6.1.7600.16385                PNP-
    ureg.dll                   6.1.7600.16385              Registry Utility DLL
    url.dll                    8.0.7600.16385              Internet Shortcut Shell Extension DLL
    urlmon.dll                 8.0.7601.17601               OLE32  Win32
    usbceip.dll                6.1.7600.16385               USBCEIP
    usbperf.dll                6.1.7600.16385               DLL   USB
    usbui.dll                  6.1.7600.16385              USB UI Dll
    user32.dll                 6.1.7601.17514                 USER API Windows
    useraccountcontrolsettings.dll  6.1.7601.17514                  
    usercpl.dll                6.1.7601.17514                
    userenv.dll                6.1.7601.17514              Userenv
    usp10.dll                  1.626.7601.18009            Uniscribe Unicode script processor
    utildll.dll                6.1.7601.17514                WinStation
    uudf.dll                   6.1.7600.16385              UDF Utility DLL
    uxinit.dll                 6.1.7600.16385              Windows User Experience Session Initialization Dll
    uxlib.dll                  6.1.7601.17514              Setup Wizard Framework
    uxlibres.dll               6.1.7600.16385              UXLib Resources
    uxtheme.dll                6.1.7600.16385                UxTheme (Microsoft)
    van.dll                    6.1.7601.17514                
    vault.dll                  6.1.7601.17514                -  Windows
    vaultcli.dll               6.1.7600.16385              Credential Vault Client Library
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbame.dll                  2.0.2.5                     VBA : Middle East Support
    vbscript.dll               5.8.7601.17866              Microsoft  VBScript
    vcamp110.dll               11.0.51106.1                Microsoft C++ AMP Runtime
    vccorlib110.dll            11.0.51106.1                Microsoft  VC WinRT core library
    vcomp100.dll               10.0.40219.1                Microsoft C/C++ OpenMP Runtime
    vcomp110.dll               11.0.51106.1                Microsoft C/C++ OpenMP Runtime
    vcomp90.dll                9.0.30729.6161              Microsoft C/C++ OpenMP Runtime
    vct3216.dll                1.6.0.12                    Voxware Compression Toolkit
    vdmdbg.dll                 6.1.7600.16385              VDMDBG.DLL
    vds_ps.dll                 6.1.7600.16385              Microsoft Virtual Disk Service proxy/stub
    vdsbas.dll                 6.1.7601.17514                  
    vdsdyn.dll                 6.1.7600.16385                  VDS,  2.1.0.1
    vdsvd.dll                  6.1.7600.16385              VDS Virtual Disk Provider, Version 1.0
    verifier.dll               6.1.7600.16385              Standard application verifier provider dll
    version.dll                6.1.7600.16385              Version Checking and File Installation Libraries
    vfwwdm32.dll               6.1.7601.17514               VfW MM Driver    WDM-
    vidreszr.dll               6.1.7600.16385              Windows Media Resizer
    virtdisk.dll               6.1.7600.16385              Virtual Disk API DLL
    vpnikeapi.dll              6.1.7601.17514              VPN IKE API's
    vss_ps.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 6.1.7601.17514              Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               6.1.7600.16385                    Microsoft
    w32topl.dll                6.1.7600.16385              Windows NT Topology Maintenance Tool
    wab32.dll                  6.1.7601.17699              Microsoft (R) Contacts DLL
    wab32res.dll               6.1.7600.16385               Microsoft (R) DLL
    wabsyncprovider.dll        6.1.7600.16385                 Microsoft Windows
    wavemsp.dll                6.1.7601.17514              Microsoft Wave MSP
    wbemcomn.dll               6.1.7601.17514              WMI
    wcnapi.dll                 6.1.7600.16385              Windows Connect Now - API Helper DLL
    wcncsvc.dll                6.1.7601.17514                Windows -   
    wcneapauthproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP Authenticator Proxy
    wcneappeerproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP PEER Proxy
    wcnwiz.dll                 6.1.7600.16385                Windows Connect Now
    wcspluginservice.dll       6.1.7600.16385               DLL WcsPlugInService
    wdc.dll                    6.1.7601.17514               
    wdi.dll                    6.1.7600.16385                Windows
    wdigest.dll                6.1.7600.16385              Microsoft Digest Access
    wdscore.dll                6.1.7601.17514              Panther Engine Module
    webcheck.dll               8.0.7601.17514               -
    webclnt.dll                6.1.7601.18201               DLL - DAV
    webio.dll                  6.1.7601.17725              API    
    webservices.dll            6.1.7601.17514                - Windows
    wecapi.dll                 6.1.7600.16385              Event Collector Configuration API
    wer.dll                    6.1.7601.17514                  Windows
    werdiagcontroller.dll      6.1.7600.16385              WER Diagnostic Controller
    werui.dll                  6.1.7600.16385               DLL      Windows
    wevtapi.dll                6.1.7600.16385              API    
    wevtfwd.dll                6.1.7600.16385              WS-Management Event Forwarding Plug-in
    wfapigp.dll                6.1.7600.16385              Windows Firewall GPO Helper dll
    wfhc.dll                   6.1.7600.16385               Windows.   
    whealogr.dll               6.1.7600.16385                WHEA
    whhelper.dll               6.1.7600.16385              DLL     winHttp
    wiaaut.dll                 6.1.7600.16385               WIA-
    wiadefui.dll               6.1.7601.17514                  WIA
    wiadss.dll                 6.1.7600.16385               WIA -  TWAIN
    wiaextensionhost64.dll     6.1.7600.16385              WIA Extension Host for thunking APIs from 32-bit to 64-bit process
    wiascanprofiles.dll        6.1.7600.16385              Microsoft Windows ScanProfiles
    wiashext.dll               6.1.7600.16385                     
    wiatrace.dll               6.1.7600.16385              WIA Tracing
    wiavideo.dll               6.1.7601.17514              WIA Video
    wimgapi.dll                6.1.7601.17514               Windows Imaging
    win32spl.dll               6.1.7601.18142                    
    winbio.dll                 6.1.7600.16385              API   Windows
    winbrand.dll               6.1.7600.16385              Windows Branding Resources
    wincredprovider.dll        6.1.7600.16385               DLL wincredprovider
    windowscodecs.dll          6.1.7601.17514              Microsoft Windows Codecs Library
    windowscodecsext.dll       6.1.7600.16385              Microsoft Windows Codecs Extended Library
    winhttp.dll                6.1.7601.17514               HTTP Windows
    wininet.dll                8.0.7601.17601                 Win32
    winipsec.dll               6.1.7600.16385              Windows IPsec SPD Client DLL
    winmm.dll                  6.1.7601.17514              MCI API DLL
    winnsi.dll                 6.1.7600.16385              Network Store Information RPC interface
    winrnr.dll                 6.1.7600.16385              LDAP RnR Provider DLL
    winrscmd.dll               6.1.7600.16385              remtsvc
    winrsmgr.dll               6.1.7600.16385              WSMan Shell API
    winrssrv.dll               6.1.7600.16385              winrssrv
    winsatapi.dll              6.1.7601.17514              Windows System Assessment Tool API
    winscard.dll               6.1.7601.17514              API - (Microsoft)
    winshfhc.dll               6.1.7600.16385              File Risk Estimation
    winsockhc.dll              6.1.7600.16385                   Winsock
    winsrpc.dll                6.1.7600.16385              WINS RPC LIBRARY
    winsta.dll                 6.1.7601.17514              Winstation Library
    winsync.dll                2007.94.7600.16385          Synchronization Framework
    winsyncmetastore.dll       2007.94.7600.16385          Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.7600.16385          Windows Synchronization Provider Framework
    wintrust.dll               6.1.7601.18205              Microsoft Trust Verification APIs
    winusb.dll                 6.1.7600.16385              Windows USB Driver User Library
    wkscli.dll                 6.1.7601.17514              Workstation Service Client DLL
    wksprtps.dll               6.1.7600.16385              WorkspaceRuntime ProxyStub DLL
    wlanapi.dll                6.1.7600.16385              Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                6.1.7600.16385               DLL    Netsh  WLAN
    wlanconn.dll               6.1.7600.16385                Dot11
    wlandlg.dll                6.1.7600.16385                   
    wlangpui.dll               6.1.7601.17514               "   "
    wlanhlp.dll                6.1.7600.16385              Windows Wireless LAN 802.11 Client Side Helper API
    wlaninst.dll               6.1.7600.16385              Windows NET Device Class Co-Installer for Wireless LAN
    wlanmm.dll                 6.1.7600.16385                Dot11   
    wlanmsm.dll                6.1.7601.17514              Windows Wireless LAN 802.11 MSM DLL
    wlanpref.dll               6.1.7601.17514                
    wlansec.dll                6.1.7600.16385              Windows Wireless LAN 802.11 MSM Security Module DLL
    wlanui.dll                 6.1.7601.17514                 
    wlanutil.dll               6.1.7600.16385               DLL     Windows   802.11
    wldap32.dll                6.1.7601.17514              Win32 LDAP API DLL
    wlgpclnt.dll               6.1.7600.16385                 802.11
    wls0wndh.dll               6.1.7600.16385              Session0 Viewer Window Hook DLL
    wmadmod.dll                6.1.7601.17514              Windows Media Audio Decoder
    wmadmoe.dll                6.1.7600.16385              Windows Media Audio 10 Encoder/Transcoder
    wmasf.dll                  12.0.7600.16385             Windows Media ASF DLL
    wmcodecdspps.dll           6.1.7600.16385              Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.7600.16385             Windows Media Device Manager Logger
    wmdmps.dll                 12.0.7600.16385             Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               12.0.7601.17514             Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               12.0.7601.17514             Windows Media DRM for Network Devices DLL
    wmdrmsdk.dll               11.0.7601.17514             Windows Media DRM SDK DLL
    wmerror.dll                12.0.7600.16385               Windows Media ()
    wmi.dll                    6.1.7601.17787              WMI DC and DP functionality
    wmidx.dll                  12.0.7600.16385             Windows Media Indexer DLL
    wmiprop.dll                6.1.7600.16385                  WDM
    wmnetmgr.dll               12.0.7601.17514             Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.7601.17514             Windows Media Player
    wmpcm.dll                  12.0.7600.16385             Windows Media Player Compositing Mixer
    wmpdui.dll                 12.0.7600.16385             Windows Media Player UI Engine
    wmpdxm.dll                 12.0.7601.17514             Windows Media Player Extension
    wmpeffects.dll             12.0.7601.17514             Windows Media Player Effects
    wmpencen.dll               12.0.7601.17514             Windows Media Player Encoding Module
    wmphoto.dll                6.1.7601.17514               Windows Media
    wmploc.dll                 12.0.7601.17514               Windows Media
    wmpmde.dll                 12.0.7601.17514             WMPMDE DLL
    wmpps.dll                  12.0.7601.17514             Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.7601.17514                Windows Media
    wmpsrcwp.dll               12.0.7601.17514             WMPSrcWp Module
    wmsgapi.dll                6.1.7600.16385              WinLogon IPC Client
    wmspdmod.dll               6.1.7601.17514              Windows Media Audio Voice Decoder
    wmspdmoe.dll               6.1.7600.16385              Windows Media Audio Voice Encoder
    wmvcore.dll                12.0.7601.17514             Windows Media Playback/Authoring DLL
    wmvdecod.dll               6.1.7601.18221              Windows Media Video Decoder
    wmvdspa.dll                6.1.7600.16385              Windows Media Video DSP Components - Advanced
    wmvencod.dll               6.1.7600.16385              Windows Media Video 9 Encoder
    wmvsdecd.dll               6.1.7601.17514              Windows Media Screen Decoder
    wmvsencd.dll               6.1.7600.16385              Windows Media Screen Encoder
    wmvxencd.dll               6.1.7600.16385              Windows Media Video Encoder
    wow32.dll                  6.1.7601.18247              Wow32
    wpc.dll                    1.0.0.1                        
    wpcao.dll                  6.1.7600.16385                WPC
    wpcsvc.dll                 1.0.0.1                         Windows
    wpdshext.dll               6.1.7601.17514                  
    wpdshserviceobj.dll        6.1.7601.17514              Windows Portable Device Shell Service Object
    wpdsp.dll                  6.1.7601.17514              WMDM Service Provider for Windows Portable Devices
    wpdwcn.dll                 6.1.7601.17514                    WCN
    ws2_32.dll                 6.1.7601.17514              32-  Windows Socket 2.0
    ws2help.dll                6.1.7600.16385              Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 6.1.7601.17514              Windows Security Center API
    wscinterop.dll             6.1.7600.16385              Windows Health Center WSC Interop
    wscisvif.dll               6.1.7600.16385              Windows Security Center ISV API
    wscmisetup.dll             6.1.7600.16385              Installers for Winsock Transport and Name Space Providers
    wscproxystub.dll           6.1.7600.16385              Windows Security Center ISV Proxy Stub
    wsdapi.dll                 6.1.7601.17514              -   DLL API- 
    wsdchngr.dll               6.1.7601.17514              WSD Challenge Component
    wsecedit.dll               6.1.7600.16385                 
    wshbth.dll                 6.1.7601.17514              Windows Sockets Helper DLL
    wshcon.dll                 5.8.7600.16385              Microsoft  Windows Script Controller
    wshelper.dll               6.1.7600.16385               DLL    Winsock Net
    wshext.dll                 5.8.7600.16385              Microsoft  Shell Extension for Windows Script Host
    wship6.dll                 6.1.7600.16385               DLL  Winsock2 (TL/IPv6)
    wshirda.dll                6.1.7601.17514              Windows Sockets Helper DLL
    wshqos.dll                 6.1.7600.16385               DLL   QoS Winsock2
    wshrm.dll                  6.1.7600.16385                DLL   Windows  PGM
    wshtcpip.dll               6.1.7600.16385               DLL   Winsock2 (TL/IPv4)
    wsmanmigrationplugin.dll   6.1.7600.16385              WinRM Migration Plugin
    wsmauto.dll                6.1.7600.16385              WSMAN Automation
    wsmplpxy.dll               6.1.7600.16385              wsmplpxy
    wsmres.dll                 6.1.7600.16385               DLL  WSMan
    wsmsvc.dll                 6.1.7601.17514               WSMan
    wsmwmipl.dll               6.1.7600.16385              WSMAN WMI Provider
    wsnmp32.dll                6.1.7601.17514              Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                6.1.7600.16385              Windows Socket 32-Bit DLL
    wtsapi32.dll               6.1.7601.17514              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  7.5.7601.17514              API    Windows
    wudriver.dll               7.5.7601.17514              Windows Update WUDriver Stub
    wups.dll                   7.5.7601.17514              Windows Update client proxy stub
    wuwebv.dll                 7.5.7601.17514              Windows Update Vista Web Control
    wvc.dll                    6.1.7601.17514              Windows Visual Components
    wwanapi.dll                6.1.7600.16385              Mbnapi
    wwapi.dll                  8.1.2.0                     WWAN API
    wzcdlg.dll                 6.1.7600.16385              Windows Connect Now - Flash Config Enrollee
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput9_1_0.dll            6.1.7600.16385                XNA
    xmlfilter.dll              2008.0.7600.16385            XML
    xmllite.dll                1.3.1001.0                  Microsoft XmlLite Library
    xmlprovi.dll               6.1.7600.16385              Network Provisioning Service Client API
    xolehlp.dll                2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsfilt.dll                6.1.7600.16385              XML Paper Specification Document IFilter
    xpsgdiconverter.dll        6.1.7601.17514              XPS to GDI Converter
    xpsprint.dll               6.1.7601.17514              XPS Printing DLL
    xpsrasterservice.dll       6.1.7601.17514              XPS Rasterization Service Component
    xpsservices.dll            6.1.7601.17514              Xps Object Model in memory creation and deserialization
    xpsshhdr.dll               6.1.7600.16385              Package Document Shell Extension Handler
    xpssvcs.dll                6.1.7600.16385              Native Code Xps Services Library
    xwizards.dll               6.1.7600.16385                 
    xwreg.dll                  6.1.7600.16385              Extensible Wizard Registration Manager Module
    xwtpdui.dll                6.1.7600.16385                   DUI
    xwtpw32.dll                6.1.7600.16385                   Win32
    zipfldr.dll                6.1.7601.17514               ZIP-


--------[   ]------------------------------------------------------------------------------------------------

     :
                         01.06.2015 3:14:56
                           01.06.2015 11:14:02
                                            01.06.2015 12:23:10
                                             4161  (0 ., 1 , 9 , 21 )

      :
                                     15.01.2015 20:21:21
                            15.01.2015 17:14:13
                                        5128439  (59 ., 8 , 33 , 59 )
                                       6690904  (77 ., 10 , 35 , 4 )
                                  62776  (0 ., 17 , 26 , 16 )
                                 83571  (0 ., 23 , 12 , 51 )
                                       306
                                43.39%

      (" "):
                                        28.05.2015 0:05:37
                                     01.06.2015 1:23:46
                                              6

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    Users                                                                              C:\Users
                                                                               D:\
                                                                                 D:\
    IPC$                            IPC            IPC                             


--------[    ]----------------------------------------------------------------------------------------------

                                           -                -
                                           -                -


--------[  ]------------------------------------------------------------------------------------------------

  [ HomeGroupUser$ ]

     :
                                         HomeGroupUser$
                                               HomeGroupUser$
                                                       
                                               HomeUsers
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                 /
                                               HomeUsers; 
                                     1
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                               HomeUsers; 
                                     2081
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[  Windows ]-----------------------------------------------------------------------------------------------

  [ NVIDIA GeForce GT 640 ]

     :
                                      NVIDIA GeForce GT 640
                                          GeForce GT 640
       BIOS                                       Version 80.7.55.0.6
                                      GeForce GT 640
       DAC                                           Integrated RAMDAC
                                            11.05.2015
                                          9.18.13.5286 - nVIDIA ForceWare 352.86
                                       NVIDIA
                                           2 

     :
      nvd3dumx                                          9.18.13.5286
      nvwgf2umx                                         9.18.13.5286
      nvwgf2umx                                         9.18.13.5286
      nvd3dum                                           9.18.13.5286 - nVIDIA ForceWare 352.86
      nvwgf2um                                          9.18.13.5286
      nvwgf2um                                          9.18.13.5286

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ NVIDIA GeForce GT 640 ]

     :
                                      NVIDIA GeForce GT 640
                                          GeForce GT 640
       BIOS                                       Version 80.7.55.0.6
                                      GeForce GT 640
       DAC                                           Integrated RAMDAC
                                            11.05.2015
                                          9.18.13.5286 - nVIDIA ForceWare 352.86
                                       NVIDIA
                                           2 

     :
      nvd3dumx                                          9.18.13.5286
      nvwgf2umx                                         9.18.13.5286
      nvwgf2umx                                         9.18.13.5286
      nvd3dum                                           9.18.13.5286 - nVIDIA ForceWare 352.86
      nvwgf2um                                          9.18.13.5286
      nvwgf2um                                          9.18.13.5286

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ NVIDIA GeForce GT 640 ]

     :
                                      NVIDIA GeForce GT 640
                                          GeForce GT 640
       BIOS                                       Version 80.7.55.0.6
                                      GeForce GT 640
       DAC                                           Integrated RAMDAC
                                            11.05.2015
                                          9.18.13.5286 - nVIDIA ForceWare 352.86
                                       NVIDIA
                                           2 

     :
      nvd3dumx                                          9.18.13.5286
      nvwgf2umx                                         9.18.13.5286
      nvwgf2umx                                         9.18.13.5286
      nvd3dum                                           9.18.13.5286 - nVIDIA ForceWare 352.86
      nvwgf2um                                          9.18.13.5286
      nvwgf2um                                          9.18.13.5286

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[  PCI / AGP ]---------------------------------------------------------------------------------------------

    nVIDIA GeForce GT 640                                                             
    nVIDIA GeForce GT 640                                                             3D-


--------[   ]---------------------------------------------------------------------------------------

  [ nVIDIA SLI ]

    nVIDIA SLI:
       SLI                                        


--------[  ]-----------------------------------------------------------------------------------------------------

  [ Samsung SyncMaster 177N/710N/MagicSyncMaster CX701N/CX711N ]

     :
                                             Samsung SyncMaster 177N/710N/MagicSyncMaster CX701N/CX711N
      ID                                        SAM011E
                                                  SyncMaster
                                             17" LCD (SXGA)
                                              43 / 2006
                                           HMELA10612
      .                         34 cm x 27 cm (17.1")
                                       5:4
                                            30 - 81 
                                           56 - 85 
                           140 
                                  1280 x 1024
                                                   2.20
        DPMS                        Active-Off

     :
      640 x 480                                         85 
      800 x 480                                         85 
      800 x 600                                         85 
      1024 x 600                                        85 
      1024 x 768                                        85 
      1152 x 864                                        85 
      1280 x 720                                        85 
      1280 x 768                                        85 
      1280 x 800                                        85 
      1280 x 1024                                       75 

     :
                                                   Samsung
                                     http://www.samsung.com/us/computer/monitors
                                       http://www.samsung.com/us/support
                                     http://www.aida64.com/driver-updates


--------[   ]------------------------------------------------------------------------------------------------

      :
                                     
                                              1280 x 1024
                                            32 
                                       1
                                        96 dpi
        /                         36 / 36
                                     51
                                      60 
                                    C:\Users\\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

      :
       -                             
                                              
                                      
                              
      ClearType                                         
             
                                
                                  
                                      
                                  
                                 
                                            
                                   
       /           
                                           
                              
                               
                            
                              
      Windows Aero                                      
       Windows Plus!                               


--------[  ]-----------------------------------------------------------------------------------------------

    \\.\DISPLAY1           (0,0)          (1280,1024)


--------[  ]-------------------------------------------------------------------------------------------------

    640 x 480           8   60 Hz
    640 x 480           8   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          16   60 Hz
    640 x 480          16   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          32   60 Hz
    640 x 480          32   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480           8   56 Hz
    720 x 480           8   56 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480           8   60 Hz
    720 x 480           8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480           8   72 Hz
    720 x 480           8   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480           8   75 Hz
    720 x 480           8   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          16   56 Hz
    720 x 480          16   56 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          16   60 Hz
    720 x 480          16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          16   72 Hz
    720 x 480          16   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          16   75 Hz
    720 x 480          16   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   56 Hz
    720 x 480          32   56 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   60 Hz
    720 x 480          32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   72 Hz
    720 x 480          32   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   75 Hz
    720 x 480          32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576           8   56 Hz
    720 x 576           8   56 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576           8   60 Hz
    720 x 576           8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576           8   72 Hz
    720 x 576           8   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576           8   75 Hz
    720 x 576           8   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          16   56 Hz
    720 x 576          16   56 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          16   60 Hz
    720 x 576          16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          16   72 Hz
    720 x 576          16   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          16   75 Hz
    720 x 576          16   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   56 Hz
    720 x 576          32   56 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   60 Hz
    720 x 576          32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   72 Hz
    720 x 576          32   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   75 Hz
    720 x 576          32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600           8   56 Hz
    800 x 600           8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600           8   75 Hz
    800 x 600          16   56 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          16   72 Hz
    800 x 600          16   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          32   60 Hz
    800 x 600          32   72 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768          8   60 Hz
    1024 x 768          8   70 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         16   60 Hz
    1024 x 768         16   70 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         32   60 Hz
    1024 x 768         32   70 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1152 x 864          8   75 Hz
    1152 x 864         16   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720          8   75 Hz
    1280 x 720          8   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         16   75 Hz
    1280 x 720         16   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   75 Hz
    1280 x 720         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768          8   75 Hz
    1280 x 768          8   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         16   75 Hz
    1280 x 768         16   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   75 Hz
    1280 x 768         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800          8   60 Hz
    1280 x 800          8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800          8   75 Hz
    1280 x 800          8   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         16   60 Hz
    1280 x 800         16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         16   75 Hz
    1280 x 800         16   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   60 Hz
    1280 x 800         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   75 Hz
    1280 x 800         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960          8   60 Hz
    1280 x 960          8   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960          8   75 Hz
    1280 x 960          8   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         16   60 Hz
    1280 x 960         16   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         16   75 Hz
    1280 x 960         16   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   60 Hz
    1280 x 960         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   75 Hz
    1280 x 960         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024         8   60 Hz
    1280 x 1024         8   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        16   75 Hz
    1280 x 1024        32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]


--------[ GPGPU ]-------------------------------------------------------------------------------------------------------

  [ CUDA: nVIDIA GeForce GT 640 (GK107) ]

     :
                                           GeForce GT 640
                                       GK107
      PCI Domain / Bus / Device                         0 / 1 / 0
                                                 901 
      Asynchronous Engines                              1
      /                             2 / 384
       L2                                            256 
      Max Threads Per Multiprocessor                    2048
      Max Threads Per Block                             1024
      Max Registers Per Block                           65536
      Max Instructions Per Kernel                       512 .
      Warp Size                                         32 threads
      Max Block Size                                    1024 x 1024 x 64
      Max Grid Size                                     2147483647 x 65535 x 65535
      Max 1D Texture Width                              65536
      Max 2D Texture Size                               65536 x 65536
      Max 3D Texture Size                               4096 x 4096 x 4096
      Max 1D Linear Texture Width                       134217728
      Max 2D Linear Texture Size                        65000 x 65000
      Max 2D Linear Texture Pitch                       1048544 
      Max 1D Layered Texture Width                      16384
      Max 1D Layered Texture Layers                     2048
      Max Mipmapped 1D Texture Width                    16384
      Max Mipmapped 2D Texture Size                     16384 x 16384
      Max Cubemap Texture Size                          16384 x 16384
      Max Cubemap Layered Texture Size                  16384 x 16384
      Max Cubemap Layered Texture Layers                2046
      Max Texture Array Size                            16384 x 16384
      Max Texture Array Slices                          2048
      Max 1D Surface Width                              65536
      Max 2D Surface Size                               65536 x 32768
      Max 3D Surface Size                               65536 x 32768 x 2048
      Max 1D Layered Surface Width                      65536
      Max 1D Layered Surface Layers                     2048
      Max 2D Layered Surface Size                       65536 x 32768
      Max 2D Layered Surface Layers                     2048
      Compute Mode                                      Default: Multiple contexts allowed per device
      Compute Capability                                3.0
      CUDA DLL                                          nvcuda.dll (8.17.13.5286 - nVIDIA ForceWare 352.86)

     :
                                           891 
      Global Memory Bus Width                           128 
      Total Memory                                      2 
      Total Constant Memory                             64 
      Max Shared Memory Per Block                       48 
      Max Memory Pitch                                  2147483647 
      Texture Alignment                                 512 
      Texture Pitch Alignment                           32 
      Surface Alignment                                 512 

     :
      32-bit Floating-Point Atomic Addition             
      32-bit Integer Atomic Operations                  
      64-bit Integer Atomic Operations                  
      Concurrent Kernel Execution                       
      Concurrent Memory Copy & Execute                  
      Double-Precision Floating-Point                   
      ECC                                               
      Funnel Shift                                       
      Host Memory Mapping                               
      Integrated Device                                 
      Stream Priorities                                  
      Surface Functions                                 
      TCC Driver                                        
      Unified Addressing                                
      Warp Vote Functions                               
      __ballot()                                        
      __syncthreads_and()                               
      __syncthreads_count()                             
      __syncthreads_or()                                
      __threadfence_system()                            

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ Direct3D: NVIDIA GeForce GT 640  ]

     :
                                           NVIDIA GeForce GT 640 
                                             nvd3dum.dll
                                          9.18.13.5286 - nVIDIA ForceWare 352.86
      Shader Model                                      SM 5.0
      Max Threads                                       1024
      Multiple UAV Access                               8 UAVs
      Thread Dispatch                                   3D
      Thread Local Storage                              32 

     :
      10-bit Precision Floating-Point                    
      16-bit Precision Floating-Point                    
      Append/Consume Buffers                            
      Atomic Operations                                 
      Double-Precision Floating-Point                   
      Gather4                                           
      Indirect Compute Dispatch                         
      Map On Default Buffers                             

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ OpenCL: nVIDIA GeForce GT 640 (GK107) ]

     OpenCL:
                                               NVIDIA CUDA
                                      NVIDIA Corporation
                                         OpenCL 1.2 CUDA 7.5.8
                                        Full

     :
                                           GeForce GT 640
                                       GK107
                                            
                                     NVIDIA Corporation
                                        OpenCL 1.2 CUDA
                                       Full
                                          352.86
       OpenCL C                                   OpenCL C 1.2 
                                                 901 
       /                       2 / 384
      Address Space Size                                32 
      Max 2D Image Size                                 16384 x 16384
      Max 3D Image Size                                 4096 x 4096 x 4096
      Max Image Array Size                              2048
      Max Image Buffer Size                             134217728
      Max Samplers                                      32
      Max Work-Item Size                                1024 x 1024 x 64
      Max Work-Group Size                               1024
      Max Argument Size                                 4352 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            9
      Max Printf Buffer Size                            1 
      Native ISA Vector Widths                          char1, short1, int1, float1, double1
      Preferred Native Vector Widths                    char1, short1, int1, long1, float1, double1
      Profiling Timer Resolution                        1000 ns
      CUDA Compute Capability                           3.0
      Max Registers Per Block                           65536
      Warp Size                                         32 threads
      Asynchronous Engines                              1
      PCI Bus / Device                                  1 / 0
      OpenCL DLL                                        opencl.dll (1.2.11.0)

     :
      Global Memory                                     2 
      Global Memory Cache                               32   (Read/Write, 128-byte line)
      Local Memory                                      48 
      Max Memory Object Allocation Size                 512 
      Memory Base Address Alignment                     4096 
      Min Data Type Alignment                           128 

     OpenCL:
      OpenCL 1.1                                          (100%)
      OpenCL 1.2                                          (100%)
      OpenCL 2.0                                          (62%)

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler Available                                
                                          
      Images                                            
      Kernel Execution                                  
      Linker Available                                  
      Little-Endian Device                              
      Native Kernel Execution                            
      SVM Atomics                                        
      SVM Coarse Grain Buffer                            
      SVM Fine Grain Buffer                              
      SVM Fine Grain System                              
      Thread Trace                                       
      Unified Memory                                    

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                 
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

     :
       /                   76 / 16
      cl_amd_bus_addressable_memory                      
      cl_amd_c1x_atomics                                 
      cl_amd_compile_options                             
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                      
      cl_amd_device_board_name                           
      cl_amd_device_memory_flags                         
      cl_amd_device_persistent_memory                    
      cl_amd_device_profiling_timer_offset               
      cl_amd_device_topology                             
      cl_amd_event_callback                              
      cl_amd_fp64                                        
      cl_amd_hsa                                         
      cl_amd_image2d_from_buffer_read_only               
      cl_amd_media_ops                                   
      cl_amd_media_ops2                                  
      cl_amd_offline_devices                             
      cl_amd_popcnt                                      
      cl_amd_predefined_macros                           
      cl_amd_printf                                      
      cl_amd_svm                                         
      cl_amd_vec3                                        
      cl_apple_contextloggingfunctions                   
      cl_apple_gl_sharing                                
      cl_apple_setmemobjectdestructor                    
      cl_ext_atomic_counters_32                          
      cl_ext_atomic_counters_64                          
      cl_ext_device_fission                              
      cl_ext_migrate_memobject                           
      cl_intel_accelerator                               
      cl_intel_ctz                                       
      cl_intel_device_partition_by_names                 
      cl_intel_dx9_media_sharing                         
      cl_intel_exec_by_local_thread                      
      cl_intel_motion_estimation                         
      cl_intel_printf                                    
      cl_intel_thread_local_exec                         
      cl_khr_3d_image_writes                             
      cl_khr_byte_addressable_store                     
      cl_khr_context_abort                               
      cl_khr_d3d10_sharing                              
      cl_khr_d3d11_sharing                               
      cl_khr_depth_images                                
      cl_khr_dx9_media_sharing                           
      cl_khr_egl_event                                   
      cl_khr_egl_image                                   
      cl_khr_fp16                                        
      cl_khr_fp64                                       
      cl_khr_gl_depth_images                             
      cl_khr_gl_event                                    
      cl_khr_gl_msaa_sharing                             
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                        
      cl_khr_image2d_from_buffer                         
      cl_khr_initialize_memory                           
      cl_khr_int64_base_atomics                          
      cl_khr_int64_extended_atomics                      
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_mipmap_image                                
      cl_khr_mipmap_image_writes                         
      cl_khr_select_fprounding_mode                      
      cl_khr_spir                                        
      cl_khr_srgb_image_writes                           
      cl_khr_subgroups                                   
      cl_khr_terminate_context                           
      cl_nv_compiler_options                            
      cl_nv_copy_opts                                   
      cl_nv_d3d10_sharing                               
      cl_nv_d3d11_sharing                               
      cl_nv_d3d9_sharing                                
      cl_nv_device_attribute_query                      
      cl_nv_pragma_unroll                               

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[  Windows ]-----------------------------------------------------------------------------------------------

    midi-out.0   0001 001B  Microsoft GS Wavetable Synth
    mixer.0      0001 0068   (Realtek High Definiti
    mixer.1      0001 0068  Mic in at front panel (Pink) (R
    mixer.2      0001 0068   (AnvSoft Virtual Sound
    mixer.3      FFFF FFFF   (5- USB2.0 Camera)
    wave-in.0    FFFF FFFF   (5- USB2.0 Camera)
    wave-in.1    0001 0065  Mic in at front panel (Pink) (R
    wave-in.2    0001 0065   (AnvSoft Virtual Sound
    wave-out.0   0001 0064   (Realtek High Definiti


--------[  PCI / PnP ]---------------------------------------------------------------------------------------------

    nVIDIA HDMI/DP @ nVIDIA GK107 - High Definition Audio Controller                  PCI
    Realtek ALC887 @ ATI SB700 - High Definition Audio Controller                     PCI


--------[ HD Audio ]----------------------------------------------------------------------------------------------------

  [ ATI SB700 - High Definition Audio Controller ]

     :
                                      ATI SB700 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        0 / 20 / 2
      ID                                      1002-4383
                               1043-8445
                                                  00
       ID                                     PCI\VEN_1002&DEV_4383&SUBSYS_84451043&REV_00

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ Realtek ALC887 ]

     :
                                      Realtek ALC887
        (Windows)                     Realtek High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10EC-0887
                               1043-8445
                                                  1003
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_10438445&REV_1003

     :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=8&PFid=14&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [ nVIDIA GK107 - High Definition Audio Controller ]

     :
                                      nVIDIA GK107 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        1 / 0 / 1
      ID                                      10DE-0E1B
                               1569-0FC1
                                                  A1
       ID                                     PCI\VEN_10DE&DEV_0E1B&SUBSYS_0FC11569&REV_A1

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ nVIDIA HDMI/DP ]

     :
                                      nVIDIA HDMI/DP
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0042
                               1569-0FC1
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0042&SUBSYS_15690FC1&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[   Windows ]-------------------------------------------------------------------------------------

  [ Generic- Multi-Card USB Device ]

     :
                                        Generic- Multi-Card USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

  [ ST500DM002-1BD142 ATA Device ]

     :
                                        ST500DM002-1BD142 ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

       :
                                           Seagate
                                   Barracuda 7200.12 500DM002
      -                                       3.5"
                                  500 
                                                   1
                                 2
                                      146.99 x 101.6 x 19.98 mm
                                         415 g
                                4.16 ms
                                        7200 RPM
      .                     1695 /
                                      8.5 ms
                                1 ms
                                               SATA-III
        '-'                600 /
                                             16 
                                          8.5 

     :
                                                   Seagate Technology LLC
                                     http://www.seagate.com/products

  [ ASUS DRW-24F1ST ATA Device ]

     :
                                        ASUS DRW-24F1ST ATA Device
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          cdrom.inf

      :
                                           Asus
                                           DVD+RW/DVD-RW/DVD-RAM
                                               SATA

     :
      DVD+R9 Dual Layer                                 8x
      DVD+R                                             24x
      DVD+RW                                            8x
      DVD-R9 Dual Layer                                 8x
      DVD-R                                             24x
      DVD-RW                                            6x
      DVD-RAM                                           5x
      CD-R                                              48x
      CD-RW                                             24x

     :
      DVD-ROM                                           16x
      CD-ROM                                            48x

     :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/Optical_Drives
                                        http://support.asus.com/download/download.aspx?SLanguage=en-us

  [ DTSOFT Virtual CdRom Device ]

     :
                                        DTSOFT Virtual CdRom Device
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          cdrom.inf

  [ HODUTKJ 74LAV01E SCSI CdRom Device ]

     :
                                        HODUTKJ 74LAV01E SCSI CdRom Device
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          cdrom.inf

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               22
                                                  FCFFFC00-FCFFFFFF
                                                    8000-800F
                                                    9000-9003
                                                    A000-A007
                                                    B000-B003
                                                    C000-C007

  [    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7601.18231
                                       Microsoft
      INF-                                          mshdc.inf

     :
                                                    FF00-FF0F


--------[   ]--------------------------------------------------------------------------------------------

    [ TRIAL VERSION ]                                NTFS      [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    D:                                               NTFS         425637      415327       10310     2 %  FA04-EFDC
    E:                                                                                                               
    F:                                                                                                                     
    G:                                                                                                               
    H:                                                                                                               


--------[   ]--------------------------------------------------------------------------------------------

  [  #1 - ST500DM002-1BD142 (465 ) ]

    #1 ()    NTFS             C:                                            101 MB    51100 MB
    #2               NTFS             D:                                          51301 MB   425638 MB


--------[   ]---------------------------------------------------------------------------------------

  [ E:\  ASUS DRW-24F1ST ATA Device ]

      :
                                      ASUS DRW-24F1ST ATA Device
                                           R94568ED101ZG6
                                          1.00
                                             1536 
                                           Asus
                                           DVD+RW/DVD-RW/DVD-RAM
                                               SATA
                                              
                               5
                                      4

     :
      DVD+R9 Dual Layer                                 8x
      DVD+R                                             24x
      DVD+RW                                            8x
      DVD-R9 Dual Layer                                 8x
      DVD-R                                             24x
      DVD-RW                                            6x
      DVD-RAM                                           5x
      CD-R                                              48x
      CD-RW                                             24x

     :
      DVD-ROM                                           16x
      CD-ROM                                            48x

      :
      BD-ROM                                             
      BD-R                                               
      BD-RE                                              
      HD DVD-ROM                                         
      HD DVD-R Dual Layer                                
      HD DVD-RW Dual Layer                               
      HD DVD-R                                           
      HD DVD-RW                                          
      HD DVD-RAM                                         
      DVD-ROM                                           
      DVD+R9 Dual Layer                                  + 
      DVD+RW9 Dual Layer                                 
      DVD+R                                              + 
      DVD+RW                                             + 
      DVD-R9 Dual Layer                                  + 
      DVD-RW9 Dual Layer                                 
      DVD-R                                              + 
      DVD-RW                                             + 
      DVD-RAM                                            + 
      CD-ROM                                            
      CD-R                                               + 
      CD-RW                                              + 

      :
      AACS                                               
      BD CPS                                             
      Buffer Underrun Protection                        
      C2 Error Pointers                                 
      CD+G                                              
      CD-Text                                           
      DVD-Download Disc Recording                        
      Hybrid Disc                                        
      JustLink                                          
      CPRM                                              
      CSS                                               
      LabelFlash                                         
      Layer-Jump Recording                              
      LightScribe                                        
      Mount Rainier                                      
      OSSC                                               
      Qflix Recording                                    
      SecurDisc                                          
      SMART                                             
      VCPS                                               

     :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/Optical_Drives
                                        http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates

  [ G:\  HODUTKJ 74LAV01E SCSI CdRom Device ]

      :
                                      HODUTKJ 74LAV01E SCSI CdRom Device
                                          1.04
                                             2 
                                              1
                               4
                                      1

      :
      BD-ROM                                            
      BD-R                                              
      BD-RE                                             
      HD DVD-ROM                                         
      HD DVD-R Dual Layer                                
      HD DVD-RW Dual Layer                               
      HD DVD-R                                           
      HD DVD-RW                                          
      HD DVD-RAM                                         
      DVD-ROM                                           
      DVD+R9 Dual Layer                                 
      DVD+RW9 Dual Layer                                
      DVD+R                                             
      DVD+RW                                            
      DVD-R9 Dual Layer                                 
      DVD-RW9 Dual Layer                                 
      DVD-R                                             
      DVD-RW                                            
      DVD-RAM                                            
      CD-ROM                                            
      CD-R                                              
      CD-RW                                             

      :
      AACS                                               
      BD CPS                                             
      Buffer Underrun Protection                         
      C2 Error Pointers                                 
      CD+G                                              
      CD-Text                                           
      DVD-Download Disc Recording                        
      Hybrid Disc                                        
      JustLink                                           
      CPRM                                               
      CSS                                                
      LabelFlash                                         
      Layer-Jump Recording                               
      LightScribe                                        
      Mount Rainier                                      
      OSSC                                               
      Qflix Recording                                    
      SecurDisc                                          
      SMART                                              
      VCPS                                               

  [ H:\  DTSOFT Virtual CdRom Device ]

      :
                                      DTSOFT Virtual CdRom Device
                                          1.05
                                             128 
                                              1
                               4
                                      1

      :
      BD-ROM                                            
      BD-R                                              
      BD-RE                                             
      HD DVD-ROM                                         
      HD DVD-R Dual Layer                                
      HD DVD-RW Dual Layer                               
      HD DVD-R                                           
      HD DVD-RW                                          
      HD DVD-RAM                                         
      DVD-ROM                                           
      DVD+R9 Dual Layer                                 
      DVD+RW9 Dual Layer                                
      DVD+R                                             
      DVD+RW                                            
      DVD-R9 Dual Layer                                 
      DVD-RW9 Dual Layer                                 
      DVD-R                                             
      DVD-RW                                            
      DVD-RAM                                            
      CD-ROM                                            
      CD-R                                              
      CD-RW                                             

      :
      AACS                                               
      BD CPS                                             
      Buffer Underrun Protection                         
      C2 Error Pointers                                 
      CD+G                                              
      CD-Text                                           
      DVD-Download Disc Recording                        
      Hybrid Disc                                        
      JustLink                                           
      CPRM                                               
      CSS                                                
      LabelFlash                                         
      Layer-Jump Recording                               
      LightScribe                                        
      Mount Rainier                                      
      OSSC                                               
      Qflix Recording                                    
      SecurDisc                                          
      SMART                                              
      VCPS                                               


--------[ ASPI ]--------------------------------------------------------------------------------------------------------

    04  00  00       HODUTKJ   74LAV01E          1.04  
    04  07  00  -             asyymqpb                          


--------[ ATA ]---------------------------------------------------------------------------------------------------------

  [ ST500DM002-1BD142 (W2AMQ5D3) ]

      ATA:
      ID                                          ST500DM002-1BD142
                                           W2AMQ5D3
                                                  KC45
      World Wide Name                                   5-000C50-05DB84848
                                           SATA-III
                                               : 969021, : 16,   : 63,   : 512
       LBA                                       976773168
       /             4  / 512 
                                                   16 
                                           16
      .  PIO                                   PIO 4
      .  MWDMA                                 MWDMA 2
      .  UDMA                                  UDMA 6
        UDMA                               UDMA 6
                                476940 
                                        7200 RPM
       ATA                                      ATA8-ACS

      ATA:
      48-bit LBA                                        , 
      Automatic Acoustic Management (AAM)               , 
      Device Configuration Overlay (DCO)                , 
      DMA Setup Auto-Activate                            
      Free-Fall Control                                  
      General Purpose Logging (GPL)                     , 
      Hardware Feature Control                           
      Host Protected Area (HPA)                         , 
      HPA Security Extensions                           , 
      Hybrid Information Feature                         
      In-Order Data Delivery                             
      Native Command Queuing (NCQ)                      
      NCQ Autosense                                      
      NCQ Priority Information                           
      NCQ Queue Management Command                       
      NCQ Streaming                                      
      Phy Event Counters                                
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      Sense Data Reporting (SDR)                         
      Service Interrupt                                  
      SMART                                             , 
      SMART Error Logging                               , 
      SMART Self-Test                                   , 
      Software Settings Preservation (SSP)              , 
      Streaming                                          
      Tagged Command Queuing (TCQ)                       
                                               , 
      Write-Read-Verify                                 , 

     SSD:
      Data Set Management                                
      Deterministic Read After TRIM                      
       TRIM                                       

     :
       (APM)                             
      Automatic Partial to Slumber Transitions (APST)   
      Device Initiated Interface Power Management (DIPM), 
      Device Sleep (DEVSLP)                              
      Extended Power Conditions (EPC)                    
      Host Initiated Interface Power Management (HIPM)   
      IDLE IMMEDIATE With UNLOAD FEATURE                 
      Link Power State Device Sleep                      
                                          , 
      Power-Up In Standby (PUIS)                         

     ATA:
      DEVICE RESET                                       
      DOWNLOAD MICROCODE                                , 
      FLUSH CACHE                                       , 
      FLUSH CACHE EXT                                   , 
      NOP                                                
      READ BUFFER                                       , 
      WRITE BUFFER                                      , 

       ATA:
                                           Seagate
                                   Barracuda 7200.12 500DM002
      -                                       3.5"
                                  500 
                                                   1
                                 2
                                      146.99 x 101.6 x 19.98 mm
                                         415 g
                                4.16 ms
                                        7200 RPM
      .                     1695 /
                                      8.5 ms
                                1 ms
                                               SATA-III
        '-'                600 /
                                             16 
                                          8.5 

     ATA-:
                                                   Seagate Technology LLC
                                     http://www.seagate.com/products
                                     http://www.aida64.com/driver-updates


--------[ SMART ]-------------------------------------------------------------------------------------------------------

  [ ST500DM002-1BD142 (W2AMQ5D3) ]

    01  Raw Read Error Rate                  6    117  99    124283080  OK:  
    03  Spinup Time                          0    99   99            0  OK:  
    04  Start/Stop Count                     20   99   99         1567  OK:  
    05  Reallocated Sector Count             36   100  100           0  OK:  
    07  Seek Error Rate                      30   76   60    251440553  OK:  
    09  Power-On Time Count                  0    90   90         8776  OK:  
    0A  Spinup Retry Count                   97   100  100           0  OK:  
    0C  Power Cycle Count                    20   99   99         1560  OK:  
    B7  <  >              0    100  100           0  OK:  
    B8  End-to-End Error                     99   100  100           0  OK:  
    BB  Reported Uncorrectable Errors        0    74   74           26  OK:  
    BC  Command Timeout                      0    100  99           12  OK:  
    BD  High Fly Writes                      0    100  100           0  OK:  
    BE  Airflow Temperature                  45   64   51    605290532  OK:  
    C2  Temperature                          0    36   49           36  OK:  
    C3  Hardware ECC Recovered               0    56   34    124283080  OK:  
    C5  Current Pending Sector Count         0    100  100           0  OK:  
    C6  Offline Uncorrectable Sector Count   0    100  100           0  OK:  
    C7  Ultra ATA CRC Error Rate             0    200  200           0  OK:  
    F0  Head Flying Hours                    0    100  253        8866  OK:  
    F1  <  >              0    100  253  4252586137  OK:  
    F2  <  >              0    100  253  3821396093  OK:  


--------[  Windows ]------------------------------------------------------------------------------------------------

  [ Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller (NDIS 6.20) ]

      :
                                          Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
                                           Gigabit Ethernet
                                         50-46-5D-B8-50-3E
                                                 
                                      100 Mbps
      MTU                                               1500 
      DHCP-                               01.06.2015 11:14:09
      DHCP-                               01.06.2015 11:14:08
                                            30699497 (29.3 )
                                          3416355 (3.3 )

      :
      IP /                                  [ TRIAL VERSION ]
                                                    [ TRIAL VERSION ]
      DHCP                                              [ TRIAL VERSION ]
      DNS                                               [ TRIAL VERSION ]

      :
                                                   Atheros Communications, Inc.
                                     http://www.atheros.com/networking
                                       http://www.atheros.com
                                     http://www.aida64.com/driver-updates


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller                             PCI


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                                       
                               

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.1.1  20   192.168.1.100 (Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller (NDIS 6.20))
                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  306  [ TRIAL VERSION ]
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
              192.168.1.0    255.255.255.0    192.168.1.100  276  192.168.1.100 (Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller (NDIS 6.20))
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  276  [ TRIAL VERSION ]
            192.168.1.255  255.255.255.255    192.168.1.100  276  192.168.1.100 (Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller (NDIS 6.20))
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  276  [ TRIAL VERSION ]
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255    192.168.1.100  276  192.168.1.100 (Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller (NDIS 6.20))


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.7601.17514   Final Retail                         70656  20.11.2010 15:18:03
    bdaplgin.ax                               6.01.7600.16385   Final Retail                      74240  14.07.2009 4:14:10
    d3d8.dll                                  6.01.7600.16385   Final Retail                    1036800  14.07.2009 4:15:08
    d3d8thk.dll                               6.01.7600.16385   Final Retail                      11264  14.07.2009 4:15:08
    d3d9.dll                                  6.01.7601.17514   Final Retail                    1828352  20.11.2010 15:18:25
    d3dim.dll                                 6.01.7600.16385   Final Retail                     386048  14.07.2009 4:15:08
    d3dim700.dll                              6.01.7600.16385   Final Retail                     817664  14.07.2009 4:15:08
    d3dramp.dll                               6.01.7600.16385   Final Retail                     593920  14.07.2009 4:15:08
    d3dxof.dll                                6.01.7600.16385   Final Retail                      53760  14.07.2009 4:15:08
    ddraw.dll                                 6.01.7600.16385   Final Retail                        531968  14.07.2009 4:15:10
    ddrawex.dll                               6.01.7600.16385   Final Retail                      30208  14.07.2009 4:15:10
    devenum.dll                               6.06.7600.16385   Final Retail                         66560  14.07.2009 4:15:10
    dinput.dll                                6.01.7600.16385   Final Retail                        136704  14.07.2009 4:15:11
    dinput8.dll                               6.01.7600.16385   Final Retail                        145408  14.07.2009 4:15:11
    dmband.dll                                6.01.7600.16385   Final Retail                      30720  14.07.2009 4:15:12
    dmcompos.dll                              6.01.7600.16385   Final Retail                      63488  14.07.2009 4:15:12
    dmime.dll                                 6.01.7600.16385   Final Retail                     179712  14.07.2009 4:15:12
    dmloader.dll                              6.01.7600.16385   Final Retail                      38400  14.07.2009 4:15:12
    dmscript.dll                              6.01.7600.16385   Final Retail                      86016  14.07.2009 4:15:12
    dmstyle.dll                               6.01.7600.16385   Final Retail                     105984  14.07.2009 4:15:12
    dmsynth.dll                               6.01.7600.16385   Final Retail                     105472  14.07.2009 4:15:12
    dmusic.dll                                6.01.7600.16385   Final Retail                        101376  14.07.2009 4:15:12
    dplaysvr.exe                              6.01.7600.16385   Final Retail                         29184  14.07.2009 4:14:18
    dplayx.dll                                6.01.7600.16385   Final Retail                     213504  14.07.2009 4:15:12
    dpmodemx.dll                              6.01.7600.16385   Final Retail                         23040  14.07.2009 4:15:12
    dpnaddr.dll                               6.01.7601.17514   Final Retail                       2560  20.11.2010 14:57:57
    dpnet.dll                                 6.01.7601.17989   Final Retail                        376832  02.11.2012 8:11:31
    dpnhpast.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnhupnp.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnlobby.dll                              6.01.7600.16385   Final Retail                       2560  14.07.2009 4:04:52
    dpnsvr.exe                                6.01.7600.16385   Final Retail                         33280  14.07.2009 4:14:18
    dpwsockx.dll                              6.01.7600.16385   Final Retail                         44032  14.07.2009 4:15:12
    dsdmo.dll                                 6.01.7600.16385   Final Retail                     173568  14.07.2009 4:15:13
    dsound.dll                                6.01.7600.16385   Final Retail                        453632  14.07.2009 4:15:13
    dswave.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:13
    dxdiagn.dll                               6.01.7601.17514   Final Retail                        210432  20.11.2010 15:18:36
    dxmasf.dll                                12.00.7601.17514  Final Retail                       4096  20.11.2010 15:21:22
    encapi.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:14
    gcdef.dll                                 6.01.7600.16385   Final Retail                        120832  14.07.2009 4:15:22
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  14.07.2009 4:14:10
    ir41_32.ax                                4.51.0016.0003    Final Retail                        839680  14.07.2009 4:14:10
    ir41_qc.dll                               4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir41_qcx.dll                              4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir50_32.dll                               5.2562.0015.0055  Final Retail                        746496  14.07.2009 4:15:34
    ir50_qc.dll                               5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ir50_qcx.dll                              5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  14.07.2009 4:14:10
    joy.cpl                                   6.01.7600.16385   Final Retail                        138240  14.07.2009 4:14:09
    ksproxy.ax                                6.01.7601.17514   Final Retail                     193536  20.11.2010 15:16:52
    kstvtune.ax                               6.01.7601.17514   Final Retail                         84480  20.11.2010 15:16:52
    ksuser.dll                                6.01.7600.16385   Final Retail                       4608  14.07.2009 4:15:35
    kswdmcap.ax                               6.01.7601.17514   Final Retail                        107008  20.11.2010 15:16:52
    ksxbar.ax                                 6.01.7601.17514   Final Retail                         48640  20.11.2010 15:16:52
    mciqtz32.dll                              6.06.7601.17514   Final Retail                         36352  20.11.2010 15:19:32
    mfc40.dll                                 4.01.0000.6151    Beta Retail                         954752  20.11.2010 15:19:33
    mfc42.dll                                 6.06.8064.0000    Beta Retail                        1137664  11.03.2011 8:33:59
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  29.03.2014 22:43:36
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  29.03.2014 22:43:36
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  29.03.2014 22:43:36
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  29.03.2014 22:43:33
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  29.03.2014 22:43:34
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  29.03.2014 22:43:34
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  29.03.2014 22:43:34
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  29.03.2014 22:43:35
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  29.03.2014 22:43:35
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  29.03.2014 22:43:35
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  29.03.2014 22:43:35
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  29.03.2014 22:43:35
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  29.03.2014 22:43:36
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  29.03.2014 22:43:36
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  29.03.2014 22:43:36
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  29.03.2014 22:43:37
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  29.03.2014 22:43:37
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  29.03.2014 22:43:36
    mpeg2data.ax                              6.06.7601.17514   Final Retail                      72704  20.11.2010 15:16:52
    mpg2splt.ax                               6.06.7601.17528   Final Retail                     199680  23.12.2010 8:50:23
    msdmo.dll                                 6.06.7601.17514   Final Retail                      30720  20.11.2010 15:19:46
    msdvbnp.ax                                6.06.7601.17514   Final Retail                      59904  20.11.2010 15:16:52
    msvidctl.dll                              6.05.7601.17514   Final Retail                       2291712  20.11.2010 15:19:55
    msyuv.dll                                 6.01.7601.17514   Final Retail                      22528  20.11.2010 15:19:56
    pid.dll                                   6.01.7600.16385   Final Retail                      36352  14.07.2009 4:16:12
    psisdecd.dll                              6.06.7601.17669   Final Retail                     465408  17.08.2011 7:24:12
    psisrndr.ax                               6.06.7601.17669   Final Retail                      75776  17.08.2011 7:19:27
    qasf.dll                                  12.00.7601.17514  Final Retail                     206848  20.11.2010 15:20:57
    qcap.dll                                  6.06.7601.17514   Final Retail                        190976  20.11.2010 15:20:57
    qdv.dll                                   6.06.7601.17514   Final Retail                        283136  20.11.2010 15:20:57
    qdvd.dll                                  6.06.7601.17713   Final Retail                        514560  26.10.2011 7:32:11
    qedit.dll                                 6.06.7601.18175   Final Retail                        509440  04.06.2013 7:53:07
    qedwipes.dll                              6.06.7600.16385   Final Retail                     733184  14.07.2009 4:09:35
    quartz.dll                                6.06.7601.17713   Final Retail                       1328128  26.10.2011 7:32:11
    vbisurf.ax                                6.01.7601.17514   Final Retail                      33792  20.11.2010 15:16:52
    vfwwdm32.dll                              6.01.7601.17514   Final Retail                         56832  20.11.2010 15:21:34
    wsock32.dll                               6.01.7600.16385   Final Retail                         15360  14.07.2009 4:16:20


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       nvd3dum.dll (9.18.13.5286 - nVIDIA ForceWare 352.86)
                                      NVIDIA GeForce GT 640 

     Direct3D:
      /                         2048  / 1580 
                                8, 16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x, CSAA 8x, CSAA 8xQ, CSAA 16x, CSAA 16xQ
                               1 x 1
                              16384 x 16384
                              5.0
        DirectX                      DirectX v11.0

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Compute Shader                                    
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      DirectX Texture Compression                        
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Double-Precision Floating-Point                   
      Driver Concurrent Creates                         
      Driver Command Lists                              
      Dynamic Textures                                  
      Edge Anti-Aliasing                                
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Geometry Shader                                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Map On Default Buffers                             
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Runtime Shader Linking                             
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Tiled Resources                                    
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                    
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      3x11                                              
      3x16                                              
      AI44                                              
      AIP8                                              
      ATOC                                              
      AV12                                              
      AYUV                                              
      NV12                                              
      NV24                                              
      NVDB                                              
      NVDP                                              
      NVMD                                              
      P010                                              
      PLFF                                              
      SSAA                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (Realtek High Definition Audio) ]

     DirectSound:
                                       (Realtek High Definition Audio)
                                          {0.0.0.00000000}.{93c0eb16-1900-4f90-89bd-65681a2decdc}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [  ]

     DirectInput:
                                      
                                           
                                        
                                                     3
      /                                    3

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [  ]

     DirectInput:
                                      
                                           
                                        
      /                                    128

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ USB Keyboard ]

     DirectInput:
                                      USB Keyboard
                                           
                                        
      /                                    3

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ USB Keyboard ]

     DirectInput:
                                      USB Keyboard
                                           
                                        
      /                                    573

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ USB Optical Mouse ]

     DirectInput:
                                      USB Optical Mouse
                                           
                                        

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ AMD K15 - Address Map ]

     :
                                      AMD K15 - Address Map
       /  /                        0 / 24 / 1
      ID                                      1022-1601
                               0000-0000
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ AMD K15 - DRAM Controller ]

     :
                                      AMD K15 - DRAM Controller
       /  /                        0 / 24 / 2
      ID                                      1022-1602
                               0000-0000
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ AMD K15 - HyperTransport Technology Configuration ]

     :
                                      AMD K15 - HyperTransport Technology Configuration
       /  /                        0 / 24 / 0
      ID                                      1022-1600
                               0000-0000
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ AMD K15 - Miscellaneous Control 2 ]

     :
                                      AMD K15 - Miscellaneous Control 2
       /  /                        0 / 24 / 4
      ID                                      1022-1604
                               0000-0000
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ AMD K15 - Miscellaneous Control 3 ]

     :
                                      AMD K15 - Miscellaneous Control 3
       /  /                        0 / 24 / 5
      ID                                      1022-1605
                               0000-0000
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ AMD K15 - Miscellaneous Control ]

     :
                                      AMD K15 - Miscellaneous Control
       /  /                        0 / 24 / 3
      ID                                      1022-1603
                               0000-0000
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ AMD RS780/RS880 Chipset - Host Bridge ]

     :
                                      AMD RS780/RS880 Chipset - Host Bridge
       /  /                        0 / 0 / 0
      ID                                      1022-9600
                               1043-8388
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ AMD RS780/RS880 Chipset - PCI Express Graphics Port 0 ]

     :
                                      AMD RS780/RS880 Chipset - PCI Express Graphics Port 0
       /  /                        0 / 2 / 0
      ID                                      1022-9603
                               1043-8388
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ AMD RS780/RS880 Chipset - PCI Express Port 0 ]

     :
                                      AMD RS780/RS880 Chipset - PCI Express Port 0
       /  /                        0 / 4 / 0
      ID                                      1022-9604
                               1043-8388
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller ]

     :
                                      Atheros AR8161/8165 PCI-E Gigabit Ethernet Controller
       /  /                        2 / 0 / 0
      ID                                      1969-1091
                               1043-8507
                                         0200 (Ethernet Controller)
                                                  10

  [ ATI SB700 - EHCI USB 2.0 Controller ]

     :
                                      ATI SB700 - EHCI USB 2.0 Controller
       /  /                        0 / 18 / 2
      ID                                      1002-4396
                               1043-8389
                                         0C03 (USB Controller)
                                                  00

  [ ATI SB700 - EHCI USB 2.0 Controller ]

     :
                                      ATI SB700 - EHCI USB 2.0 Controller
       /  /                        0 / 19 / 2
      ID                                      1002-4396
                               1043-8389
                                         0C03 (USB Controller)
                                                  00

  [ ATI SB700 - High Definition Audio Controller ]

     :
                                      ATI SB700 - High Definition Audio Controller
       /  /                        0 / 20 / 2
      ID                                      1002-4383
                               1043-8445
                                         0403 (High Definition Audio)
                                                  00

  [ ATI SB700 - IDE Controller ]

     :
                                      ATI SB700 - IDE Controller
       /  /                        0 / 20 / 1
      ID                                      1002-439C
                               1043-8389
                                         0101 (IDE Controller)
                                                  00

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
       /  /                        0 / 18 / 0
      ID                                      1002-4397
                               1043-8389
                                         0C03 (USB Controller)
                                                  00

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
       /  /                        0 / 18 / 1
      ID                                      1002-4398
                               1043-8389
                                         0C03 (USB Controller)
                                                  00

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
       /  /                        0 / 19 / 0
      ID                                      1002-4397
                               1043-8389
                                         0C03 (USB Controller)
                                                  00

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
       /  /                        0 / 19 / 1
      ID                                      1002-4398
                               1043-8389
                                         0C03 (USB Controller)
                                                  00

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
       /  /                        0 / 20 / 5
      ID                                      1002-4399
                               1043-8389
                                         0C03 (USB Controller)
                                                  00

  [ ATI SB700 - PCI-LPC Bridge ]

     :
                                      ATI SB700 - PCI-LPC Bridge
       /  /                        0 / 20 / 3
      ID                                      1002-439D
                               1043-8389
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ ATI SB700 - PCI-PCI Bridge ]

     :
                                      ATI SB700 - PCI-PCI Bridge
       /  /                        0 / 20 / 4
      ID                                      1002-4384
                               0000-0000
                                         0800 (Programmable Interrupt Controller)
                                                  00

  [ ATI SB700 - SATA Controller ]

     :
                                      ATI SB700 - SATA Controller
       /  /                        0 / 17 / 0
      ID                                      1002-4390
                               1043-8389
                                         0101 (IDE Controller)
                                                  00

  [ ATI SB700 - SMBus Controller ]

     :
                                      ATI SB700 - SMBus Controller
       /  /                        0 / 20 / 0
      ID                                      1002-4385
                               1043-8389
                                         0800 (Programmable Interrupt Controller)
                                                  3C

  [ nVIDIA GK107 - High Definition Audio Controller ]

     :
                                      nVIDIA GK107 - High Definition Audio Controller
       /  /                        1 / 0 / 1
      ID                                      10DE-0E1B
                               1569-0FC1
                                         0403 (High Definition Audio)
                                                  A1

  [ Palit GeForce GT 640 Video Adapter ]

     :
                                      Palit GeForce GT 640 Video Adapter
       /  /                        1 / 0 / 0
      ID                                      10DE-0FC1
                               1569-0FC1
                                         0300 (VGA Display Controller)
                                                  A1

  [ ULi/ALi M5281 SATA/RAID Controller ]

     :
                                      ULi/ALi M5281 SATA/RAID Controller
       /  /                        0 / 0 / 0
      ID                                      10B9-5281
                               7750-38C2
                                                  01


--------[  USB ]----------------------------------------------------------------------------------------------

  [ GT-S7562 (Android) ]

     :
                                      GT-S7562
      ID                                      04E8-6860
                                         06 / 01 (Imaging)
                                      01
                                           Android
                                                 Android
                                           965751c2
        USB                         2.00
                                         High  (USB 2.0)

  [    USB (USB2.0-CRW) ]

     :
                                         USB
      ID                                      0BDA-0158
                                         08 / 06 (Mass Storage)
                                      50
                                           Generic
                                                 USB2.0-CRW
                                           20060413092100000
        USB                         2.00
                                         High  (USB 2.0)

  [  USB  (USB2.0 Camera) ]

     :
                                       USB 
      ID                                      1871-0141
                                         EF / 02 (Interface Association Descriptor)
                                      01
                                           AVEO Technology Corp.
                                                 USB2.0 Camera
        USB                         2.00
                                         High  (USB 2.0)

  [ USB-  (USB Optical Mouse) ]

     :
                                      USB- 
      ID                                      1BCF-0007
                                         03 / 01 (Human Interface Device)
                                      02
                                                 USB Optical Mouse
        USB                         2.00
                                         Low  (USB 1.1)

  [  USB  (USB Keyboard) ]

     :
                                       USB 
      ID                                      1A2C-0B23
                                         03 / 01 (Human Interface Device)
                                      01
                                           USB
                                                 USB Keyboard
        USB                         1.10
                                         Low  (USB 1.1)

  [ USB-  (USB OPTICAL MOUSE) ]

     :
                                      USB- 
      ID                                      15D9-0A4D
                                         03 / 01 (Human Interface Device)
                                      02
                                                 USB OPTICAL MOUSE
        USB                         1.10
                                         Low  (USB 1.1)


--------[  ]------------------------------------------------------------------------------------------------

    AdobeAAMUpdater-1.0                Registry\Common\Run      C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe 
    AllInform                          Registry\User\Run        C:\Program Files (x86)\AllInform\AllInformWin.exe 
    ccleaner                           Registry\User\Run        C:\Program Files\CCleaner\CCleaner64.exe /AUTO
    DAEMON Tools Pro Agent             Registry\User\Run        C:\Program Files\DAEMON Tools Pro\DTAgent.exe -autorun
    egui                               Registry\Common\Run      C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe /hide /waitservice
    ProfitTaskMonitor                  StartMenu\User           C:\Program Files (x86)\ProfitTask\ProfitTaskMonitor.exe 
    Sidebar                            Registry\User\Run        C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    SunJavaUpdateSched                 Registry\Common\Run      C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 
    Viber                              Registry\User\Run        C:\Users\\AppData\Local\Viber\Viber.exe StartMinimized


--------[   ]-------------------------------------------------------------------------------------

    Torrent                                                                               3.3.1.30017    uTorrent                                      BitTorrent Inc.                           
    Torrent                                                                               3.3.1.30017    uTorrent                                      BitTorrent Inc.                           
    ACDSee [ TRIAL VERSION ]                                                                   7.1.163    {FCDC1C [ TRIAL VERSION ]                     ACD Systems International Inc.  2014-12-03
    Adobe  [ TRIAL VERSION ]                                                                17.0.0.134    Adobe F [ TRIAL VERSION ]                     Adobe Systems Incorporated                
    Adobe  [ TRIAL VERSION ]                                                                   11.0.04    {AC76BA [ TRIAL VERSION ]                     Adobe Systems Incorporated      2013-09-30
    Advego [ TRIAL VERSION ]                                                                              {86819F [ TRIAL VERSION ]                     Advego, Ltd.                    2014-12-06
    AIDA64 [ TRIAL VERSION ]                                                                 3.00.2500    AIDA64_ [ TRIAL VERSION ]                     l-rePack                       2013-08-04
    AIMP3 [ TRIAL VERSION ]                                                           v3.55.1350, 16.06.2014    AIMP3 [ TRIAL VERSION ]                       AIMP DevTeam                    2014-07-04
    AllInf [ TRIAL VERSION ]                                                                     1.0.7    {5DE448 [ TRIAL VERSION ]                     AllInform.co                    2015-05-18
    Any Vi [ TRIAL VERSION ]                                                                              Any Vid [ TRIAL VERSION ]                     Any-Video-Converter.com         2014-05-04
    ASUS P [ TRIAL VERSION ]                                                                   1.0.014    {49BE9B [ TRIAL VERSION ]                     ASUS                            2013-08-04
    ASUSUp [ TRIAL VERSION ]                                                                   7.18.03    {587178 [ TRIAL VERSION ]                     ASUSTeK Computer Inc.                     
    Athero [ TRIAL VERSION ]                                                                 2.0.11.12    {3108C2 [ TRIAL VERSION ]                     Atheros Communications Inc.     2013-05-26
    ATI Ca [ TRIAL VERSION ]                                                                 3.0.762.0    {62140B [ TRIAL VERSION ]                     ATI Technologies, Inc.          2013-05-26
    Battle [ TRIAL VERSION ]                                                                              Battlef [ TRIAL VERSION ]                     R.G. Mechanics, markfiter       2015-01-28
    Battle [ TRIAL VERSION ]                                                                              Battlef [ TRIAL VERSION ]                     R.G. Mechanics, markfiter       2014-12-17
    Boilso [ TRIAL VERSION ]                                                                              {245490 [ TRIAL VERSION ]                     Boilsoft, Inc.                  2013-07-30
    Cars 2 [ TRIAL VERSION ]                                                          Cars 2.The Video Game    Cars 2. [ TRIAL VERSION ]                     Fenixx--Repack--(28.06.2011)    2015-02-07
    CClean [ TRIAL VERSION ]                                                                      3.24    CCleane [ TRIAL VERSION ]                     Piriform                        2012-11-06
    Comman [ TRIAL VERSION ]                                                                      1.09    {DDEDAF [ TRIAL VERSION ]                     -=Hooli G@n=-                   2014-07-08
    CyberL [ TRIAL VERSION ]                                                                       5.0    Install [ TRIAL VERSION ]                     CyberLink Corp.                 2014-04-20
    DAEMON Tools Pro 4.41.0315.0262                                                     4.41.0315.0262    DAEMON Tools Pro_is1                          l-rePack                       2015-02-03
    EasyCleaner []                                                                 2.0.6.380    {F5346614-B7C4-4E94-826A-E2363155233D}        ToniArts                        2013-09-27
    EPSON Printer Software                                                                                EPSON Printer and Utilities                                                             
    ESET NOD32 Antivirus [ ()]                                                  4.2.67.10    {5163DC54-F9BB-4219-AC7C-DFDD5CACD66B}        ESET, spol. s r.o.              2013-05-26
    Etxt Antiplagiat [ ()]                                                         3.0.49    {6E7FDCC5-E283-47B6-BE1E-DA8BE280B207}        Inet-trade                      2014-12-05
    Google Chrome                                                                         28.0.1500.95    Google Chrome                                 Google Inc.                     2013-05-27
    Google Update Helper                                                                    1.3.21.145    {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}        Google Inc.                     2013-05-27
    Java 8 Update 45 (64-bit)                                                                  8.0.450    {26A24AE4-039D-4CA4-87B4-2F86418045F0}        Oracle Corporation              2015-04-23
    Java Auto Updater                                                                        2.8.45.14    {4A03706F-666A-4037-7777-5F2748764D10}        Oracle Corporation              2015-04-23
    Microsoft .NET Framework 4.5.2 (RUS) [ ()]                                  4.5.51209    {8D41AED1-7B35-340D-8960-589E08EA4FF1}                    2014-12-03
    Microsoft .NET Framework 4.5.2 ()                                                 4.5.51209    {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1049                        
    Microsoft .NET Framework 4.5.2                                                           4.5.51209    {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033  Microsoft Corporation                     
    Microsoft .NET Framework 4.5.2                                                           4.5.51209    {26784146-6E05-3FF9-9335-786C7C0FB5BE}        Microsoft Corporation           2014-12-03
    Microsoft Office -    2003 [ ()]              11.0.5614.0 - Office 2003 RTM    {90120419-6000-11D3-8CFE-0150048383C9}        Microsoft Corporation           2013-10-24
    Microsoft Visual C++ 2005 Redistributable (x64)                                          8.0.56336    {071c9b48-7c32-4621-a0ac-3f809523288f}        Microsoft Corporation           2013-07-12
    Microsoft Visual C++ 2005 Redistributable                                                8.0.56336    {7299052b-02a4-4627-81f2-1818da5d550d}        Microsoft Corporation           2013-07-02
    Microsoft Visual C++ 2005 Redistributable                                                8.0.59193    {837b34e3-7c30-493c-8f6a-2b0f04e2912c}        Microsoft Corporation           2013-06-30
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 [ ()]             9.0.21022    {D04659D1-EB2D-3DE5-A833-837A623CCCF7}        Microsoft Corporation           2014-03-29
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17                             9.0.30729    {9A25302D-30C0-39D9-BD6F-21E6EC160475}        Microsoft Corporation           2013-05-29
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161                      9.0.30729.6161    {9BE518E6-ECC6-35A9-88E4-87755C07200F}        Microsoft Corporation           2014-12-17
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219                             10.0.40219    {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}        Microsoft Corporation           2013-11-09
    Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219                              10.0.40219    {1D8E6291-B0D5-35EC-8441-6616F567A0F7}        Microsoft Corporation           2013-11-12
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030                          11.0.61030.0    {a2199617-3609-410f-a8e8-e8806c73545b}                              
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610                          11.0.60610.1    {01db25f3-1b76-4d97-88c8-1c90634d88fb}                              
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030                          11.0.61030.0    {f0080ca2-80ae-4958-b6eb-e8fa916d744a}                              
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030                           11.0.61030    {37B8F9C7-03FB-3253-8781-2517C99D7C00}        Microsoft Corporation           2014-12-17
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030                              11.0.61030    {CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}        Microsoft Corporation           2014-12-17
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030                           11.0.61030    {B175520C-86A2-35A7-8619-86DC379688B9}        Microsoft Corporation           2014-12-17
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030                              11.0.61030    {BD95A8CD-1D9F-35AD-981A-3E7925026EBB}        Microsoft Corporation           2014-12-17
    Microsoft_VC80_ATL_x86_x64                                                          8.0.50727.4053    {925D058B-564A-443A-B4B2-7E90C6432E55}        Adobe                           2015-03-22
    Microsoft_VC80_ATL_x86                                                              8.0.50727.4053    {0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}        Adobe                           2015-03-22
    Microsoft_VC80_CRT_x86_x64                                                          8.0.50727.4053    {4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}        Adobe                           2015-03-22
    Microsoft_VC80_CRT_x86                                                              8.0.50727.4053    {92D58719-BBC1-4CC3-A08B-56C9E884CC2C}        Adobe                           2015-03-22
    Microsoft_VC80_MFC_x86_x64                                                          8.0.50727.4053    {C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}        Adobe                           2015-03-22
    Microsoft_VC80_MFC_x86                                                              8.0.50727.4053    {D1A19B02-817E-4296-A45B-07853FD74D57}        Adobe                           2015-03-22
    Microsoft_VC80_MFCLOC_x86_x64                                                        80.50727.4053    {1E9FC118-651D-4934-97BE-E53CAE5C7D45}        Adobe                           2015-03-22
    Microsoft_VC80_MFCLOC_x86                                                           8.0.50727.4053    {D92BBB52-82FF-42ED-8A3C-4E062F944AB7}        Adobe                           2015-03-22
    Microsoft_VC90_ATL_x86_x64                                                               1.00.0000    {8557397C-A42D-486F-97B3-A2CBC2372593}        Adobe                           2015-03-22
    Microsoft_VC90_ATL_x86                                                                   1.00.0000    {033E378E-6AD3-4AD5-BDEB-CBD69B31046C}        Adobe                           2015-03-22
    Microsoft_VC90_CRT_x86_x64                                                               1.00.0000    {92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}        Adobe                           2015-03-22
    Microsoft_VC90_CRT_x86                                                                   1.00.0000    {08D2E121-7F6A-43EB-97FD-629B44903403}        Adobe                           2015-03-22
    Microsoft_VC90_MFC_x86_x64                                                               1.00.0000    {A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}        Adobe                           2015-03-22
    Microsoft_VC90_MFC_x86                                                                   1.00.0000    {635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}        Adobe                           2015-03-22
    Mozilla Firefox 38.0.1 (x86 uk)                                                             38.0.1    Mozilla Firefox 38.0.1 (x86 uk)               Mozilla                                   
    Mozilla Maintenance Service                                                                   35.0    MozillaMaintenanceService                     Mozilla                                   
    MPC-HC 1.7.1 (64-bit)                                                                      1.7.1.0    {2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1    MPC-HC Team                     2014-12-06
    MSXML 4.0 SP2 (KB973688)                                                               4.20.9876.0    {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}        Microsoft Corporation           2013-06-06
    MyFreeCodec                                                                                           MyFreeCodec                                                                             
    MyFreeCodec                                                                                           MyFreeCodec                                                                             
    Nero Micro XCV edition                                                                    9.4.13.2    Nero Micro                                                                              
    neroxml                                                                                      1.0.0    {56C049BE-79E9-4502-BEA7-9754A3E60F9B}        Nero AG                         2013-11-12
    NVIDIA Install Application [ ()]                                  2.1002.175.1474    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer  NVIDIA Corporation              2015-06-01
    NVIDIA  HD 1.3.34.3 [ ()]                                    1.3.34.3    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver  NVIDIA Corporation              2015-06-01
    NVIDIA   352.86 [ ()]                                    352.86    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver  NVIDIA Corporation              2015-06-01
    NVIDIA   3D Vision 352.65 [ ()]                          352.65    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB  NVIDIA Corporation              2015-06-01
    NVIDIA    PhysX 9.15.0428 [ ()]          9.15.0428    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX  NVIDIA Corporation              2015-06-01
    Opera 12.17                                                                             12.17.1863    Opera 12.17.1863                              Opera Software ASA                        
    Opera Stable 29.0.1795.60                                                             29.0.1795.60    Opera 29.0.1795.60                            Opera Software ASA                        
    QIP Shot 3.4                                                                                 3.4.3    QIP Shot_is1                                  OOO Media Mir                   2014-12-06
    RaidCall                                                                          7.2.4-1.0.7299.14    RaidCall                                      raidcall.com                              
    Realtek High Definition Audio Driver []                                       6.0.1.6873    {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}        Realtek Semiconductor Corp.     2013-09-14
    Registry Life,  1.63                                                                    1.63    Registry Life_is1                             ChemTable Software              2013-10-04
    Serious Sam (Gold Edition)                                                        Serious Sam (Gold Edition)    Serious Sam (Gold Edition)_is1                                                2015-04-11
    Skype Click to Call                                                                 7.3.16540.9015    {6D1221A9-17BF-4EC0-81F2-27D30EC30701}        Microsoft Corporation           2014-08-10
    Skype 6.21                                                                               6.21.104    {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}        Skype Technologies S.A.         2014-11-23
    TapinRadio 1.60.1                                                                                     TapinRadio_is1                                Raimersoft                      2015-02-05
    The KMPlayer 2.9.4.1435 (DXVA+CUDA+SVP)                                                               The KMPlayer 2.9.4.1435 (DXVA+CUDA+SVP)_is1   7sh3. [  01.05.2010]   2015-01-31
    TuneUp Utilities 2012                                                                12.0.3600.114    {32364CEA-7855-4A3C-B674-53D8E9B97936}        TuneUp Software                 2013-06-02
    TuneUp Utilities 2012                                                                12.0.3600.114    TuneUp Utilities 2012                         TuneUp Software                           
    TuneUp Utilities Language Pack (ru-RU)                                                 12.0.2120.7    {A95A76C9-6F65-477E-83A0-9F884B6DC21B}        TuneUp Software                 2013-06-02
    Unity  [ TRIAL VERSION ]                                                                   4.5.0f6    UnityWe [ TRIAL VERSION ]                     Unity Technologies ApS                    
    Unity  [ TRIAL VERSION ]                                                                   4.5.0f6    UnityWe [ TRIAL VERSION ]                     Unity Technologies ApS                    
    VC80CR [ TRIAL VERSION ]                                                                     1.2.0    {933B40 [ TRIAL VERSION ]                     DivX, Inc                       2013-09-06
    Viber [ TRIAL VERSION ]                                                                   5.1.1.15    Viber [ TRIAL VERSION ]                       Viber Media Inc                           
    Viber [ TRIAL VERSION ]                                                                   5.1.1.15    Viber [ TRIAL VERSION ]                       Viber Media Inc                           
    VKMusi [ TRIAL VERSION ]                                                                      4.63    VKMusic [ TRIAL VERSION ]                                                     2015-02-17
    VLC me [ TRIAL VERSION ]                                                                     2.0.7    VLC med [ TRIAL VERSION ]                     VideoLAN                                  
    Window [ TRIAL VERSION ]                                                                     2.7.6    {069B43 [ TRIAL VERSION ]                     Taurin                          2014-01-07
    WinRAR [ TRIAL VERSION ]                                                               5.10.1.1267    WinRAR  [ TRIAL VERSION ]                                                     2013-05-26
    World  [ TRIAL VERSION ]                                                                              {1EAC1D [ TRIAL VERSION ]                     Wargaming.net                   2014-11-22
    World  [ TRIAL VERSION ]                                                                              {1EAC1D [ TRIAL VERSION ]                     Wargaming.net                   2014-11-22
    World  [ TRIAL VERSION ]                                                                              {1EAC1D [ TRIAL VERSION ]                     Wargaming.net                   2015-04-19
    World  [ TRIAL VERSION ]                                                                              {1EAC1D [ TRIAL VERSION ]                     Wargaming.net                   2015-04-19
    World  [ TRIAL VERSION ]                                                                              {1EAC1D [ TRIAL VERSION ]                     Wargaming.net                   2015-03-23
    Xvid MPEG-4 Video Codec                                                                               xvid                                          Xvid Development Team                     
      NVIDIA 352.86 [ ()]                                      352.86    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel  NVIDIA Corporation              2015-06-01
     -                                                                                    -                                                                     
    .   [RUS]                                                                            {60B5AAF3-D91A-4320-8680-EBCE2BDEB8EE}_is1    R.G. ReCoding - by Donald Dark , Inc.  2015-03-22
    .   [RUS]                                                                              {0656DA62-B133-4467-99C9-8BEA3D531A75}_is1    R.G. ReCoding - by Donald Dark , Inc.  2015-03-22
    .                                                                                      .                                                                        
                                                                                                                                                                                        
     MultiPack                                                                            0.9.8    {1EAC1D02-C6AC-4FA6-9A44-96258C37C812MP}_is1  Copyright (C) PROTanki          2015-05-31


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       [ TRIAL VERSION ]
      Winlogon Shell                                    explorer.exe
          (UAC)  
                                   

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  ]---------------------------------------------------------------------------------------------------

    NOD32                                                4.2.67.10                                01.06.2015         ?


--------[  ]--------------------------------------------------------------------------------------------------

     Windows                              6.1.7600.16385  


--------[   ]--------------------------------------------------------------------------------------------

    Microsoft Windows Defender                6.1.7600.16385(win7_rtm.090713-1255)


--------[   ]--------------------------------------------------------------------------------------

     :
                                     ()
                            (UTC+02:00) , , , , , 
                               Last Sunday of October 4:00:00
                                    Last Sunday of March 3:00:00

    :
       (.)                                      
       (.)                                      Ukrainian
       (ISO 639)                                    uk

    /:
       (.)                                    
       (.)                                    Ukraine
       (ISO 3166)                                 UA
                                               380

     :
        (.)                          
        (.)                          Ukrainian Grivna
         (.)                   ?
         (ISO 4217)                UAH
                                      123456789,00?
                         -123456789,00?

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy' .'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                           ' / 
                                            / 
                                        / 

    :
                                            ѳ / ѳ
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0409h                                         ()
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\⠫\AppData\Roaming
    CommonProgramFiles(x86)   C:\Program Files (x86)\Common Files
    CommonProgramFiles        C:\Program Files (x86)\Common Files
    CommonProgramW6432        C:\Program Files\Common Files
    COMPUTERNAME              -
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\⠫
    LOCALAPPDATA              C:\Users\⠫\AppData\Local
    LOGONSERVER               \\-
    NUMBER_OF_PROCESSORS      4
    OS                        Windows_NT
    Path                      C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_ARCHITEW6432    AMD64
    PROCESSOR_IDENTIFIER      AMD64 Family 21 Model 1 Stepping 2, AuthenticAMD
    PROCESSOR_LEVEL           21
    PROCESSOR_REVISION        0102
    ProgramData               C:\ProgramData
    ProgramFiles(x86)         C:\Program Files (x86)
    ProgramFiles              C:\Program Files (x86)
    ProgramW6432              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\99E7~1\AppData\Local\Temp
    TMP                       C:\Users\99E7~1\AppData\Local\Temp
    USERDOMAIN                ⠫-
    USERNAME                  ⠫
    USERPROFILE               C:\Users\⠫
    windir                    C:\Windows


--------[   ]---------------------------------------------------------------------------------------------

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [MCI Extensions.BAK]
    3g2=MPEGVideo
    3gp=MPEGVideo
    3gp2=MPEGVideo
    3gpp=MPEGVideo
    aac=MPEGVideo
    adt=MPEGVideo
    adts=MPEGVideo
    m2t=MPEGVideo
    m2ts=MPEGVideo
    m2v=MPEGVideo
    m4a=MPEGVideo
    m4v=MPEGVideo
    mod=MPEGVideo
    mov=MPEGVideo
    mp4=MPEGVideo
    mp4v=MPEGVideo
    mts=MPEGVideo
    ts=MPEGVideo
    tts=MPEGVideo
    [Mail]
    CMCDLLNAME32=mapi32.dll
    CMCDLLNAME=mapi.dll
    CMC=1
    MAPI=1
    MAPIX=1
    MAPIXVER=1.0.0.1
    OLEMessaging=1

  [ hosts ]

    
    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\\AppData\Roaming
    Cache                        C:\Users\\AppData\Local\Microsoft\Windows\Temporary Internet Files
    CD Burning                   C:\Users\\AppData\Local\Microsoft\Windows\Burn\Burn
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\\Favorites
    Common Files (x86)           C:\Program Files (x86)\Common Files
    Common Files                 C:\Program Files (x86)\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\\AppData\Roaming\Microsoft\Windows\Cookies
    Desktop                      C:\Users\\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\\AppData\Local
    My Documents                 C:\Users\\Documents
    My Music                     C:\Users\\Music
    My Pictures                  C:\Users\\Pictures
    My Video                     C:\Users\\Videos
    NetHood                      C:\Users\\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\
    Program Files (x86)          C:\Program Files (x86)
    Program Files                C:\Program Files (x86)
    Programs                     C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System (x86)                 C:\Windows\SysWOW64
    System                       C:\Windows\system32
    Temp                         C:\Users\99E7~1\AppData\Local\Temp\
    Templates                    C:\Users\\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                 101        2015-05-27 21:16:04                                  Application Hang                1002: 
                 100        2015-05-30 16:01:41                                  Application Error               1000:   : Cars.exe, : 0.0.0.0,  : 0x446e3753    : ntdll.dll, : 6.1.7601.18247,   0x521ea8e7   : 0xc0000005   : 0x0002e41b    : 0x930     : 0x01d09ad110af55e9    : D:\Games\Cars\Cars.exe    : C:\Windows\SysWOW64\ntdll.dll   : 03958fc9-06cc-11e5-909a-50465db8503e
                 100        2015-05-30 17:19:49                                  Application Error               1000:   : Cars.exe, : 0.0.0.0,  : 0x446e3753    : ntdll.dll, : 6.1.7601.18247,   0x521ea8e7   : 0xc0000005   : 0x0002e41b    : 0x1c4     : 0x01d09ad928fa0ee9    : D:\Games\Cars\Cars.exe    : C:\Windows\SysWOW64\ntdll.dll   : eda741d3-06d6-11e5-909a-50465db8503e
                 100        2015-05-30 21:48:03                                  Application Error               1000:   : ufdsvc.exe, : 1.0.0.7,  : 0x43f2cc17    : ufdsvc.exe, : 1.0.0.7,   0x43f2cc17   : 0xc0000005   : 0x00006b7f    : 0x764     : 0x01d09b0914baa837    : C:\Windows\SysWOW64\ufdsvc.exe    : C:\Windows\SysWOW64\ufdsvc.exe   : 66414cfc-06fc-11e5-89ec-50465db8503e
                 100        2015-05-30 23:43:43                                  Application Error               1000:   : VKMusic4.exe, : 1.0.10.272,  : 0x54d7523d    : ntdll.dll, : 6.1.7601.18247,   0x521ea8e7   : 0xc0000005   : 0x0002f367    : 0xe18     : 0x01d09b18aae49ef1    : C:\Program Files (x86)\VKMusic 4\VKMusic4.exe    : C:\Windows\SysWOW64\ntdll.dll   : 8f468800-070c-11e5-89ec-50465db8503e
                 101        2015-05-31 01:51:37                                  Application Hang                1002: 
                 100        2015-05-31 21:51:25                                  Application Error               1000:   : kmplayer.exe, : 2.9.4.1435,  : 0x4993e3a7    : kmplayer.exe, : 2.9.4.1435,   0x4993e3a7   : 0xc0000005   : 0x000074ee    : 0x9e4     : 0x01d09bcfb40704a2    : C:\Program Files (x86)\KMPlayer\kmplayer.exe    : C:\Program Files (x86)\KMPlayer\kmplayer.exe   : 094cd8ce-07c6-11e5-8d7f-50465db8503e
                 100        2015-06-01 01:24:08                                  Application Error               1000:   : ufdsvc.exe, : 1.0.0.7,  : 0x43f2cc17    : ufdsvc.exe, : 1.0.0.7,   0x43f2cc17   : 0xc0000005   : 0x00006b7f    : 0x738     : 0x01d09bf0793ae86f    : C:\Windows\SysWOW64\ufdsvc.exe    : C:\Windows\SysWOW64\ufdsvc.exe   : c06831a5-07e3-11e5-aeb0-50465db8503e
                 100        2015-06-01 01:24:40                                  Application Error               1000:   : Viber.exe, : 5.1.1.15,  : 0x55633427    : MSVCR100.dll, : 10.0.40219.325,   0x4df2be1e   : 0x40000015   : 0x0008d6fd    : 0xb60     : 0x01d09bf0848e347a    : C:\Users\\AppData\Local\Viber\Viber.exe    : C:\Users\\AppData\Local\Viber\MSVCR100.dll   : d39d12b4-07e3-11e5-aeb0-50465db8503e
      Audit Success   12288      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-25 22:15:33                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb55c  
      Audit Success   12290      2015-05-25 22:15:38                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-25 22:15:40                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-25 22:15:40                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-25 22:15:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x31038   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-25 22:15:44                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-25 22:15:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x328ea   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-25 22:15:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32913   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-25 22:15:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x328ea    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-25 22:16:14                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-25 22:16:14                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-25 22:17:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-25 22:17:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-25 22:22:56                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x2ec   :  C:\Windows\System32\svchost.exe     :  2015-05-25T19:22:56.899384600Z   :  2015-05-25T19:22:56.899000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2015-05-25 22:33:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-25 22:33:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-26 00:35:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 00:35:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-26 01:29:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 01:29:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-26 01:36:45                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32913      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-26 01:36:50                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-26 22:03:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa5f1  
      Audit Success   12290      2015-05-26 22:03:56                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-26 22:03:57                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-26 22:03:58                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-26 22:04:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x30569   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-26 22:04:00                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-26 22:04:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x31490   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-26 22:04:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x314b1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 22:04:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x31490    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-26 22:04:36                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-26 22:04:36                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-26 22:04:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 22:04:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-26 22:06:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 22:06:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-26 22:07:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 22:07:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-26 22:22:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 22:22:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-26 23:28:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 23:28:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-26 23:50:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-26 23:50:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-27 02:39:10                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x314b1      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-27 02:39:13                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-27 21:13:22                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-27 21:13:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-27 21:13:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-27 21:13:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-27 21:13:22                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa5fa  
      Audit Success   12544      2015-05-27 21:13:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-27 21:13:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-27 21:13:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-27 21:13:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-27 21:13:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-27 21:13:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-27 21:13:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-27 21:13:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-27 21:13:27                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-27 21:13:30                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-27 21:13:30                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-27 21:13:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x32610   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-27 21:13:33                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-27 21:13:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32adb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-27 21:13:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32b1d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-27 21:13:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32adb    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-27 21:13:59                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-27 21:13:59                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-27 21:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-27 21:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-27 21:15:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-27 21:15:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-27 23:13:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-27 23:13:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-28 00:05:33                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xbec6  
      Audit Success   12544      2015-05-28 00:05:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 00:05:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 00:05:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 00:05:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-28 00:05:42                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-28 00:05:45                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-28 00:05:46                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-28 00:05:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x32430   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 00:05:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-28 00:05:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32e2d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 00:05:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32e56   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 00:05:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32e2d    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-28 00:06:25                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-28 00:06:25                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-28 00:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 00:08:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-28 01:52:55                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32e56      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-28 01:52:57                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-28 08:21:47                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa8ad  
      Audit Success   12290      2015-05-28 08:21:51                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-28 08:21:54                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-28 08:21:55                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-28 08:21:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x30b5b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 08:21:57                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-28 08:21:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3125e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 08:21:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x31280   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 08:21:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3125e    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-28 08:22:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 08:22:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-28 08:22:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-28 08:22:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-28 08:24:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 08:24:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-28 09:37:32                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-28 09:37:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 09:37:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 09:37:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-28 09:37:32                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xacb6  
      Audit Success   12544      2015-05-28 09:37:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 09:37:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 09:37:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 09:37:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 09:37:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 09:37:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 09:37:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 09:37:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-05-28 09:37:34                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12290      2015-05-28 09:37:37                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-28 09:37:39                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-28 09:37:39                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-28 09:37:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2cf9b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 09:37:50                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x240    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-28 09:37:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x31101   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 09:37:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3112c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 09:37:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x31101    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-28 09:39:45                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3112c      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-28 09:39:46                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-28 22:20:17                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-28 22:20:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 22:20:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 22:20:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 22:20:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 22:20:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-28 22:20:17                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa802  
      Audit Success   12544      2015-05-28 22:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 22:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 22:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 22:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 22:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-28 22:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-28 22:20:21                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-28 22:20:23                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-28 22:20:24                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-28 22:20:25                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-28 22:20:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2fd9a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-28 22:20:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2fdbb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 22:20:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2fd9a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-28 22:20:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x33e9d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12290      2015-05-28 22:21:09                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-28 22:21:09                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-28 22:22:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 22:22:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-28 22:24:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 22:24:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-28 22:31:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-28 22:31:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-29 02:04:19                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2fdbb      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-29 02:04:21                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-29 08:33:00                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7c7  
      Audit Success   12290      2015-05-29 08:33:03                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-29 08:33:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-29 08:33:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-29 08:33:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x31809   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 08:33:09                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-29 08:33:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x327f1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 08:33:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32813   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 08:33:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x327f1    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-29 08:33:44                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-29 08:33:44                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-29 08:35:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 08:35:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-29 09:03:28                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-29 09:03:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-05-29 09:03:28                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xc118  
      Audit Success   12544      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 09:03:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-29 09:03:35                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-29 09:03:37                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-29 09:03:39                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-29 09:03:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x325c0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 09:03:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-29 09:03:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x336b6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 09:03:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x336db   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 09:03:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x336b6    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-29 09:04:16                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-29 09:04:16                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-29 09:05:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 09:05:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-29 09:30:14                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x336db      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-29 09:30:16                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-29 21:17:19                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb405  
      Audit Success   12290      2015-05-29 21:17:22                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-29 21:17:23                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2015-05-29 21:17:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2d461   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12292      2015-05-29 21:17:28                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-29 21:17:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-29 21:17:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x31c98   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 21:17:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x31cc1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 21:17:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x31c98    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-29 21:18:14                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-29 21:18:14                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-29 21:18:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 21:18:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-29 21:19:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 21:19:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-29 22:23:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 22:23:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-29 22:41:18                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-29 22:41:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-05-29 22:41:18                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaf60  
      Audit Success   12544      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-29 22:41:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-29 22:41:21                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-29 22:41:22                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-29 22:41:26                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-29 22:41:28                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-29 22:41:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32d5b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 22:41:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32d7c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-29 22:41:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x32e4a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 22:41:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32d5b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-29 22:42:18                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-29 22:42:18                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-29 22:43:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-29 22:43:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-29 22:59:16                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x32d7c      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-29 22:59:17                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-30 13:10:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb11f  
      Audit Success   12290      2015-05-30 13:10:43                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-30 13:10:44                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-30 13:10:44                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-30 13:10:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2c2d1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 13:10:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-30 13:10:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x331d2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 13:10:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x331fd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 13:10:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x331d2    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 13:12:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 13:12:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 15:02:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 15:02:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-30 15:05:38                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xba6d  
      Audit Success   12290      2015-05-30 15:05:41                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-30 15:05:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-30 15:05:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-30 15:05:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x305ed   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 15:05:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-30 15:05:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x316b9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 15:05:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x316da   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 15:05:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x316b9    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 15:06:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 15:06:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 15:08:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 15:08:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 16:01:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 16:01:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 17:19:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 17:19:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-30 17:21:29                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x316da      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-30 17:21:36                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-30 17:22:47                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb542  
      Audit Success   12544      2015-05-30 17:22:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 17:22:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 17:22:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 17:22:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-30 17:22:51                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-30 17:22:52                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-30 17:22:53                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-30 17:22:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29c00   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 17:23:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-30 17:23:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3f138   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 17:23:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3f191   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 17:23:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3f138    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 17:25:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 17:25:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 19:57:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 19:57:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-30 20:00:11                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3f191      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-30 20:00:14                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-30 21:47:18                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-30 21:47:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 21:47:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 21:47:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-30 21:47:18                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb4f8  
      Audit Success   12544      2015-05-30 21:47:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 21:47:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 21:47:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 21:47:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 21:47:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 21:47:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 21:47:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-30 21:47:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-30 21:47:22                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-30 21:47:23                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-30 21:47:26                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-30 21:47:29                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-30 21:47:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x30e80   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 21:47:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x30ea9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 21:47:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x30e80    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 21:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x34330   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-30 21:47:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 21:47:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-30 21:48:25                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-30 21:48:25                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-30 21:49:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 21:49:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 22:36:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 22:36:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 22:44:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 22:44:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 22:58:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 22:58:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 23:08:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 23:08:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 23:18:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 23:18:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 23:39:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 23:39:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-30 23:43:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-30 23:43:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-31 00:00:16                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-31 00:00:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 00:00:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 00:00:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-31 00:00:16                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb779  
      Audit Success   12544      2015-05-31 00:00:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 00:00:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 00:00:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 00:00:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 00:00:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-31 00:00:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-31 00:00:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-31 00:00:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-31 00:00:25                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-31 00:00:26                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-31 00:00:27                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-31 00:00:29                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-31 00:00:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2edf9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 00:00:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2ee1a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 00:00:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2edf9    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-31 00:00:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x32978   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12290      2015-05-31 00:01:15                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-31 00:01:15                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-31 00:02:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 00:02:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-31 00:05:41                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x35c   :  C:\Windows\System32\svchost.exe     :  2015-05-30T21:05:45.670794500Z   :  2015-05-30T21:05:41.862109600Z          .    Windows,    ,    .           .  
      Audit Success   12288      2015-05-31 00:05:41                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x35c   :  C:\Windows\System32\svchost.exe     :  2015-05-30T21:05:41.894109600Z   :  2015-05-30T21:05:41.894000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2015-05-31 00:05:41                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x35c   :  C:\Windows\System32\svchost.exe     :  2015-05-30T21:05:41.896000100Z   :  2015-05-30T21:05:41.896000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2015-05-31 01:34:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 01:34:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-31 01:47:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 01:47:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-31 01:51:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 01:51:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-05-31 02:20:01                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2ee1a      ,   .  ,  ,  .        .  
      Audit Success   103        2015-05-31 02:20:04                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-05-31 21:16:37                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb036  
      Audit Success   12290      2015-05-31 21:16:42                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-05-31 21:16:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-05-31 21:16:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-05-31 21:16:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-05-31 21:16:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3050d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 21:16:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3052e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 21:16:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3050d    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-31 21:16:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3507f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-05-31 21:17:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 21:17:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-05-31 21:17:30                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-05-31 21:17:30                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-05-31 21:19:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 21:19:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-05-31 21:20:00                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x15c   :  C:\Windows\System32\svchost.exe     :  2015-05-31T18:20:00.170370700Z   :  2015-05-31T18:20:00.170000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2015-05-31 21:51:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 21:51:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-31 22:25:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 22:25:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-05-31 22:43:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-05-31 22:43:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-06-01 00:35:46                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-06-01 00:35:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:35:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:35:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:35:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 00:35:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-06-01 00:35:46                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xbd24  
      Audit Success   12544      2015-06-01 00:35:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:35:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:35:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:35:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 00:35:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 00:35:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-06-01 00:35:51                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-06-01 00:35:53                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-06-01 00:35:54                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-06-01 00:35:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x320b2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:35:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-06-01 00:35:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x33419   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:35:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x33442   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:35:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x33419    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-06-01 00:36:40                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-06-01 00:36:40                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-06-01 00:38:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:38:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-06-01 00:41:12                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x3bc   :  C:\Windows\System32\svchost.exe     :  2015-05-31T21:41:12.053555300Z   :  2015-05-31T21:41:12.053000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2015-06-01 00:50:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:50:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-06-01 00:57:55                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x33442      ,   .  ,  ,  .        .  
      Audit Success   103        2015-06-01 00:57:56                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-06-01 00:58:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-06-01 00:58:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:58:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:58:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-06-01 00:58:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb29f  
      Audit Success   12544      2015-06-01 00:58:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:58:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:58:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:58:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:58:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 00:58:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 00:58:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 00:58:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-06-01 00:58:43                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-06-01 00:58:45                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-06-01 00:58:46                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-06-01 00:58:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-06-01 00:58:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2f25f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:58:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2f291   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:58:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2f25f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-06-01 00:58:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x324b6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 00:59:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 00:59:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-06-01 00:59:24                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-06-01 00:59:24                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-06-01 01:01:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 01:01:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-06-01 01:04:01                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x218   :  C:\Windows\System32\svchost.exe     :  2015-05-31T22:04:01.788691500Z   :  2015-05-31T22:04:01.788000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-06-01 01:23:41                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xc870  
      Audit Success   101        2015-06-01 01:23:42                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12290      2015-06-01 01:23:44                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-06-01 01:23:47                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-06-01 01:23:47                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-06-01 01:23:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-06-01 01:23:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2f08d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 01:23:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2f0b5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 01:23:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2f08d    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-06-01 01:23:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x342f9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 01:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 01:24:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-06-01 01:24:31                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-06-01 01:24:31                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-06-01 01:26:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 01:26:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-06-01 02:27:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 02:27:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-06-01 03:14:50                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x2f0b5      ,   .  ,  ,  .        .  
      Audit Success   103        2015-06-01 03:14:51                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-06-01 11:14:01                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-06-01 11:14:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 11:14:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 11:14:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-06-01 11:14:01                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb77e  
      Audit Success   12544      2015-06-01 11:14:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 11:14:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 11:14:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 11:14:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 11:14:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 11:14:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 11:14:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-06-01 11:14:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-06-01 11:14:05                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Success   12292      2015-06-01 11:14:07                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-06-01 11:14:09                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-06-01 11:14:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2fef2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 11:14:14                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-06-01 11:14:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x30864   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-06-01 11:14:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x3088d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 11:14:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-316864040-2520155316-4209367544-1000     :       :  -    :  0x30864    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2015-06-01 11:14:57                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : RSA    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2015-06-01 11:14:57                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : %%2432    : 0c84f199-e510-4569-b048-0e5e0d286760    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf6333244c7a958be3b1e13fa7774d8_f23da4b0-8e7a-4302-aecc-d2de7879abd8   : %%2458    : 0x0  
      Audit Success   12544      2015-06-01 11:16:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 11:16:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-06-01 12:20:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-06-01 12:20:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
                  212        2015-05-25 22:15:58                           Microsoft-Windows-Kernel-PnP    219: 
                          2015-05-26 01:17:50  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     domdeneg.kz        DNS.  
                            2015-05-26 01:36:40                                  DCOM                            
                          2015-05-26 01:36:57                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-26 22:04:17                           Microsoft-Windows-Kernel-PnP    219: 
                          2015-05-27 02:39:15                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-27 21:13:44                           Microsoft-Windows-Kernel-PnP    219: 
                          2015-05-27 22:06:20  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     google-analytics.bi.owox.com        DNS.  
                  212        2015-05-28 00:05:31                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-05-28 00:05:35                                  EventLog                        6008:      0:04:23  ?28.?05.?2015  .  
                            2015-05-28 00:05:37                                  BugCheck                        
                          2015-05-28 01:52:58                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-28 08:22:18                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-05-28 09:37:33                                  EventLog                        6008:      9:35:48  ?28.?05.?2015  .  
                  212        2015-05-28 09:37:54                           Microsoft-Windows-Kernel-PnP    219: 
                          2015-05-28 09:39:46                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-28 22:20:48                           Microsoft-Windows-Kernel-PnP    219: 
                          2015-05-29 02:04:23                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-29 08:33:25                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-05-29 09:03:29                                  EventLog                        6008:      9:02:00  ?29.?05.?2015  .  
                            2015-05-29 09:03:32                                  BugCheck                        
                  212        2015-05-29 09:03:52                           Microsoft-Windows-Kernel-PnP    219: 
                          2015-05-29 09:30:16                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-29 21:17:44                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-05-29 22:41:20                                  EventLog                        6008:      22:40:22  ?29.?05.?2015  .  
                  212        2015-05-29 22:41:20                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-05-29 22:41:24                                  BugCheck                        
                          2015-05-29 22:59:17                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-30 13:10:56                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-05-30 15:05:38                                  EventLog                        6008:      15:02:39  ?30.?05.?2015  .  
                  212        2015-05-30 15:06:06                           Microsoft-Windows-Kernel-PnP    219: 
                          2015-05-30 17:21:43                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-30 17:23:02                           Microsoft-Windows-Kernel-PnP    219: 
                  3          2015-05-30 19:50:23                           Microsoft-Windows-Resource-Exhaustion-Detector  2004:       .        :  carsmn.exe (3296)  411639808 ,  Viber.exe (2612)  143601664    ekrn.exe (1340)  102227968 .  
                  3          2015-05-30 19:55:22                           Microsoft-Windows-Resource-Exhaustion-Detector  2004:       .        :  carsmn.exe (3296)  420937728 ,  Viber.exe (2612)  143605760    ekrn.exe (1340)  102227968 .  
                          2015-05-30 20:00:16                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-30 21:47:58                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-05-30 21:48:10                                  Service Control Manager         7034: 
                          2015-05-30 22:32:24  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     offers.bittorrent.com        DNS.  
                  212        2015-05-31 00:00:14                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-05-31 00:00:17                                  EventLog                        6008:      23:59:19  ?30.?05.?2015  .  
                            2015-05-31 00:00:24                                  BugCheck                        
                          2015-05-31 02:20:09                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-05-31 21:17:11                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-06-01 00:35:47                                  EventLog                        6008:      0:34:41  ?01.?06.?2015  .  
                            2015-06-01 00:35:52                                  BugCheck                        
                  212        2015-06-01 00:36:08                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-06-01 00:50:50                                  volsnap                         36: 
                            2015-06-01 00:50:57                                  DCOM                            
                          2015-06-01 00:57:57                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-06-01 00:59:10                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-06-01 01:23:41                                  EventLog                        6008:      1:19:40  ?01.?06.?2015  .  
                            2015-06-01 01:23:46                                  BugCheck                        
                            2015-06-01 01:24:09                                  Service Control Manager         7034: 
                  212        2015-06-01 01:24:09                           Microsoft-Windows-Kernel-PnP    219: 
                          2015-06-01 03:14:52                           Microsoft-Windows-WLAN-AutoConfig  4001: 
                  212        2015-06-01 11:14:36                           Microsoft-Windows-Kernel-PnP    219: 


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
