Time Stamp Log Name SourceNode Message
01/01/2000 01:01:01 009B9178,Update=009B7F78,New=009B7FC8,Status=Success,ReturnCode=0 10-06-2008 14:17:15,Update=BroadcomNetXtremeGigabit Ethernet Drivers - Microsoft Digitally Signed,New=Version 8.1B4 -[BCOM81B4-8.1B4]-,Status=Unknown,ReturnCode=1618 10-06-2008 14:17:32,Update=BroadcomNetXtremeGigabit Ethernet Drivers - Microsoft Digitally Signed,New=Version 8.1B4 -[BCOM81B4-8.1B4]-,Status=Unknown,ReturnCode=1618 009B9178,Update=009B7F78,New=009B7FC8,Status=Success,ReturnCode=0
10/06/2008 13:29:57 SystemEvent The NetBIOS name and DNS host name of this machine have been changed from MACHINENAME to QMGSBC-DC1.
10/06/2008 13:30:15 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: MACHINENAME$ Caller Domain: Caller Logon ID: (0x0,0x3E7) Caller Process ID: 276 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 13:30:15 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/06/2008 13:30:15 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 13:30:15 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: MACHINENAME$ Caller Domain: Caller Logon ID: (0x0,0x3E7) Caller Process ID: 276 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 13:30:15 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 13:38:35 SystemEvent Windows Server 2003 Hotfix KB911164 was installed.
10/06/2008 13:43:56 SystemEvent Setup successfully installed Windows build 3790.
10/06/2008 13:43:57 SystemEvent The process winlogon.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Upgrade (Planned) Reason Code: 0x80020003 Shutdown Type: restart Comment: Windows setup has completed, and the computer must restart.
10/06/2008 13:43:58 SystemEvent The Event log service was stopped.
10/06/2008 13:43:58 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
10/06/2008 13:45:20 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/06/2008 13:45:34 SystemEvent The Event log service was started.
10/06/2008 13:45:34 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 1 Multiprocessor Free.
10/06/2008 13:45:36 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/06/2008 13:45:37 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 13:45:37 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 13:45:37 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 456 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 13:45:37 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 13:45:37 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 456 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 13:45:42 SystemEvent The Application Experience Lookup service started successfully.
10/06/2008 13:45:42 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
10/06/2008 13:45:43 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB78D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
10/06/2008 13:46:00 SecurityEvent Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10A86) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 13:46:00 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 13:46:00 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10A86) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 412 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 13:46:00 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 412 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 13:47:19 SystemEvent The start type of the Distributed File System service was changed from auto start to demand start.
10/06/2008 13:47:19 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
10/06/2008 13:47:19 SystemEvent The Computer Browser service entered the stopped state.
10/06/2008 13:47:19 SystemEvent The Windows Installer service entered the running state.
10/06/2008 13:47:19 SystemEvent The Network Location Awareness (NLA) service entered the running state.
10/06/2008 13:47:19 SystemEvent The Terminal Services service entered the running state.
10/06/2008 13:47:19 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
10/06/2008 13:47:19 SystemEvent The Application Layer Gateway Service service entered the running state.
10/06/2008 13:47:19 SystemEvent Timeout (30000 milliseconds) waiting for a transaction response from the Dfs service.
10/06/2008 13:47:19 SystemEvent The Terminal Services service was successfully sent a start control.
10/06/2008 13:47:19 SystemEvent The Windows Installer service was successfully sent a start control.
10/06/2008 13:48:43 SystemEvent Windows Server 2003 R2 Hotfix R2-In-band was installed.
10/06/2008 13:49:16 SystemEvent MMC 3.0 Hotfix MMC30Core was installed.
10/06/2008 13:49:38 SystemEvent Windows Server 2003 R2 Hotfix R2-New-files was installed.
10/06/2008 13:56:25 SystemEvent The Windows Installer service entered the stopped state.
10/06/2008 14:12:30 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x61807) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 412 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 14:12:30 SecurityEvent Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x61807) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 14:12:30 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x61807) Logon Type: 7
10/06/2008 14:12:30 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 412 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 14:12:30 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 14:16:11 SystemEvent The Windows Installer service entered the running state.
10/06/2008 14:16:11 SystemEvent The Windows Installer service was successfully sent a start control.
10/06/2008 14:16:31 SystemEvent Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link.
10/06/2008 14:16:31 SystemEvent Broadcom NetXtreme Gigab: Driver initialized successfully.
10/06/2008 14:16:32 SystemEvent The Remote Access Connection Manager service was successfully sent a start control.
10/06/2008 14:16:32 SystemEvent The Telephony service entered the running state.
10/06/2008 14:16:34 SystemEvent The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.
10/06/2008 14:16:34 SystemEvent The Remote Access Connection Manager service entered the running state.
10/06/2008 14:16:37 SystemEvent Broadcom NetXtreme Gigab: Driver initialized successfully.
10/06/2008 14:16:38 SystemEvent Broadcom NetXtreme Gigab: Driver initialized successfully.
10/06/2008 14:16:38 SystemEvent Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link.
10/06/2008 14:16:39 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time.
10/06/2008 14:16:39 SystemEvent Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link.
10/06/2008 14:16:41 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time.
10/06/2008 14:17:29 SystemEvent Broadcom NetXtreme Gigab: Driver initialized successfully.
10/06/2008 14:17:30 SystemEvent Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link.
10/06/2008 14:17:33 SystemEvent Broadcom NetXtreme Gigab: Driver initialized successfully.
10/06/2008 14:17:34 SystemEvent Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link.
10/06/2008 14:17:49 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10a86)
10/06/2008 14:17:49 SystemEvent The Windows Installer service entered the stopped state.
10/06/2008 14:17:49 SystemEvent The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: g
10/06/2008 14:17:53 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
10/06/2008 14:17:53 SystemEvent The Event log service was stopped.
10/06/2008 14:19:18 SystemEvent Broadcom NetXtreme Gigab: Driver initialized successfully.
10/06/2008 14:19:18 SystemEvent Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link.
10/06/2008 14:19:19 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/06/2008 14:19:19 SystemEvent Broadcom NetXtreme Gigab: Driver initialized successfully.
10/06/2008 14:19:20 SystemEvent Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link.
10/06/2008 14:19:30 SystemEvent The Event log service was started.
10/06/2008 14:19:30 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 1 Multiprocessor Free.
10/06/2008 14:19:31 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/06/2008 14:19:32 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 14:19:32 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 14:19:32 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 764 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 14:19:32 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 14:19:32 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 764 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 14:20:31 SystemEvent Your computer has automatically configured the IP address for the Network Card with network address 000D609CC160. The IP address being used is 169.254.230.196.
10/06/2008 14:20:38 SystemEvent The Application Experience Lookup service started successfully.
10/06/2008 14:20:38 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
10/06/2008 14:20:39 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB753) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
10/06/2008 14:20:51 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 1 Multiprocessor Free.
10/06/2008 14:20:51 SystemEvent The Event log service was started.
10/06/2008 14:20:52 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/06/2008 14:21:13 SystemEvent The Terminal Services service was successfully sent a start control.
10/06/2008 14:21:13 SystemEvent The Terminal Services service entered the running state.
10/06/2008 14:21:13 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
10/06/2008 14:21:13 SystemEvent The Application Layer Gateway Service service entered the running state.
10/06/2008 14:21:13 SystemEvent The Computer Browser service entered the stopped state.
10/06/2008 14:21:13 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
10/06/2008 14:21:13 SystemEvent The Network Location Awareness (NLA) service entered the running state.
10/06/2008 14:22:41 SecurityEvent Audit Policy Change: New Policy: Success Failure + - Logon/Logoff - - Object Access - - Privilege Use - - Account Management - - Policy Change - - System - - Detailed Tracking - - Directory Service Access + - Account Logon Changed By: User Name: MACHINENAME$ Domain Name: Logon ID: (0x0,0x3E7)
10/06/2008 14:23:24 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: ROOT\DMIO\0000 Vetoing device: Root\dmio\0000 Vetoing service name: Driver\dmio Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:23:26 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: STORAGE\VOLUME\1&30A96598&0&SIGNATUREB6F0B6F0OFFSET7E00LENGTH950280000 Vetoing device: STORAGE\Volume\1&30a96598&0&SignatureB6F0B6F0Offset7E00Length950280000 Vetoing service name: FileSystem\Ntfs Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:23:28 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: ACPI\FIXEDBUTTON\2&DABA3FF&0 Vetoing device: ACPI\FixedButton\2&daba3ff&0 Vetoing service name: Driver\ACPI Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:23:49 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: PCI\VEN_1166&DEV_0203&SUBSYS_00000000&REV_B0\3&267A616A&0&78 Vetoing device: ACPI\PNP0B00\4&3a5043f3&0 Vetoing service name: Driver\ACPI Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:23:51 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: PCI\VEN_1166&DEV_0227&SUBSYS_00000000&REV_00\3&267A616A&0&7B Vetoing device: PCI\VEN_1166&DEV_0227&SUBSYS_00000000&REV_00\3&267a616a&0&7B Vetoing service name: Driver\isapnp Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:24:03 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: PCI\VEN_1166&DEV_0213&SUBSYS_02121166&REV_B0\3&267A616A&0&79 Vetoing device: IDE\DiskTOSHIBA_MK4026GAXB______________________PB104E__\5&2c80d75&0&0.0.0 Vetoing service name: Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:24:04 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: PCIIDE\IDECHANNEL\4&FA31D19&0&0 Vetoing device: IDE\DiskTOSHIBA_MK4026GAXB______________________PB104E__\5&2c80d75&0&0.0.0 Vetoing service name: Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:24:21 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: ACPI\PNP0B00\4&3A5043F3&0 Vetoing device: ACPI\PNP0B00\4&3a5043f3&0 Vetoing service name: Driver\ACPI Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:24:39 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: IDE\DISKTOSHIBA_MK4026GAXB______________________PB104E__\5&2C80D75&0&0.0.0 Vetoing device: IDE\DiskTOSHIBA_MK4026GAXB______________________PB104E__\5&2c80d75&0&0.0.0 Vetoing service name: Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/06/2008 14:25:06 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x1661D) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 14:25:06 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1661D) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 688 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 14:25:06 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 688 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 14:25:06 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 14:32:37 SystemEvent The Automatic Updates service was successfully sent a stop control.
10/06/2008 14:32:38 SystemEvent The Automatic Updates service entered the stopped state.
10/06/2008 14:32:44 SystemEvent The Automatic Updates service was successfully sent a start control.
10/06/2008 14:32:45 SystemEvent The Automatic Updates service entered the running state.
10/06/2008 14:34:37 SystemEvent The Computer Browser service entered the running state.
10/06/2008 14:34:37 SystemEvent The Computer Browser service was successfully sent a start control.
10/06/2008 14:37:15 SystemEvent The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.
10/06/2008 14:37:15 SystemEvent The Background Intelligent Transfer Service service entered the running state.
10/06/2008 14:37:15 SystemEvent The Background Intelligent Transfer Service service was successfully sent a start control.
10/06/2008 14:37:16 SystemEvent The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.
10/06/2008 14:37:16 SystemEvent The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.
10/06/2008 14:37:22 SystemEvent The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.
10/06/2008 14:37:22 SystemEvent The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.
10/06/2008 14:37:23 SystemEvent The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.
10/06/2008 14:38:20 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1661D) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {293015a8-9170-4d3f-4558-52e85980f3b5} Target Server Name: qmgsdc1.qmgs.internal Target Server Info: cifs/qmgsdc1.qmgs.internal Caller Process ID: 792 Source Network Address: - Source Port: -
10/06/2008 14:53:17 SystemEvent Windows Server 2003 Service Pack 2 was installed (Service Pack 1 was previously installed).
10/06/2008 14:55:23 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 688 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 14:55:23 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1101BF) Logon Type: 7
10/06/2008 14:55:23 SecurityEvent Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1101BF) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 14:55:23 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1101BF) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 688 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 14:55:23 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 14:55:37 SystemEvent The process winlogon.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Operating System: Service pack (Planned) Reason Code: 0x80020010 Shutdown Type: restart Comment: Windows Server 2003 Service Pack 2
10/06/2008 14:55:37 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1661d)
10/06/2008 14:55:42 SystemEvent The Event log service was stopped.
10/06/2008 14:55:42 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
10/06/2008 14:57:13 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
10/06/2008 14:57:14 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
10/06/2008 14:57:15 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/06/2008 14:57:29 SystemEvent The Event log service was started.
10/06/2008 14:57:29 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
10/06/2008 14:57:30 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/06/2008 14:57:32 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 14:57:32 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 14:57:32 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 14:57:32 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 14:57:32 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 14:57:46 SystemEvent The Application Experience Lookup service started successfully.
10/06/2008 14:57:46 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
10/06/2008 14:57:49 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD90A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
10/06/2008 14:58:11 SystemEvent The Help and Support service entered the stopped state.
10/06/2008 14:58:11 SystemEvent The Help and Support service was successfully sent a stop control.
10/06/2008 14:58:11 SystemEvent The Distributed Transaction Coordinator service entered the running state.
10/06/2008 14:58:11 SystemEvent The Distributed Transaction Coordinator service was successfully sent a start control.
10/06/2008 14:58:11 SystemEvent The Distributed Transaction Coordinator service entered the stopped state.
10/06/2008 14:58:11 SystemEvent The Distributed Transaction Coordinator service was successfully sent a stop control.
10/06/2008 14:58:11 SystemEvent The Application Layer Gateway Service service entered the running state.
10/06/2008 14:58:11 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
10/06/2008 14:58:11 SystemEvent The Network Location Awareness (NLA) service entered the running state.
10/06/2008 14:58:11 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
10/06/2008 14:58:11 SystemEvent The Terminal Services service was successfully sent a start control.
10/06/2008 14:58:11 SystemEvent The Terminal Services service entered the running state.
10/06/2008 14:58:12 SystemEvent The Help and Support service entered the running state.
10/06/2008 14:58:12 SystemEvent The WinHTTP Web Proxy Auto-Discovery Service service was successfully sent a start control.
10/06/2008 14:58:12 SystemEvent The WinHTTP Web Proxy Auto-Discovery Service service entered the running state.
10/06/2008 14:58:12 SystemEvent The Help and Support service was successfully sent a start control.
10/06/2008 14:58:22 SystemEvent The Windows Service Pack Installer update service service entered the stopped state.
10/06/2008 15:01:41 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x320A4) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 15:01:41 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x320A4) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 15:01:41 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 15:01:41 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 15:02:39 SystemEvent The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: Image upload
10/06/2008 15:02:40 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x320a4)
10/06/2008 15:02:44 SystemEvent The Event log service was stopped.
10/06/2008 15:02:44 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
10/06/2008 15:05:21 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
10/06/2008 15:05:22 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
10/06/2008 15:05:25 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/06/2008 15:05:38 SystemEvent The Event log service was started.
10/06/2008 15:05:38 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
10/06/2008 15:05:39 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/06/2008 15:05:41 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:05:41 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:05:41 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 15:05:41 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 15:05:41 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:05:49 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
10/06/2008 15:05:49 SystemEvent The Application Experience Lookup service started successfully.
10/06/2008 15:05:50 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB536) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:06:40 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 15:06:40 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 15:06:40 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x122AB) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 15:06:40 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x122AB) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 15:06:59 SystemEvent The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: Image upload
10/06/2008 15:06:59 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x122ab)
10/06/2008 15:07:01 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x122AB) Logon Type: 2
10/06/2008 15:07:05 SystemEvent The Event log service was stopped.
10/06/2008 15:07:05 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
10/06/2008 15:12:29 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
10/06/2008 15:12:29 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/06/2008 15:12:30 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
10/06/2008 15:12:43 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
10/06/2008 15:12:43 SystemEvent The Event log service was started.
10/06/2008 15:12:44 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/06/2008 15:12:46 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:12:46 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 15:12:46 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 15:12:46 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:12:46 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:12:54 SystemEvent The Application Experience Lookup service started successfully.
10/06/2008 15:12:55 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
10/06/2008 15:12:56 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xCDAD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:14:18 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
10/06/2008 15:14:18 SystemEvent The Application Layer Gateway Service service entered the running state.
10/06/2008 15:14:18 SystemEvent The Network Location Awareness (NLA) service entered the running state.
10/06/2008 15:14:18 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
10/06/2008 15:14:18 SystemEvent The Terminal Services service was successfully sent a start control.
10/06/2008 15:14:18 SystemEvent The Terminal Services service entered the running state.
10/06/2008 15:27:12 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 15:27:12 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x16BEE) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 15:27:12 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x16BEE) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 15:27:12 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 15:27:24 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x16bee)
10/06/2008 15:27:24 SystemEvent The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: g
10/06/2008 15:27:28 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
10/06/2008 15:27:28 SystemEvent The Event log service was stopped.
10/06/2008 15:46:17 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
10/06/2008 15:46:17 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/06/2008 15:46:18 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
10/06/2008 15:46:29 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/06/2008 15:46:29 SystemEvent The Event log service was started.
10/06/2008 15:46:29 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
10/06/2008 15:46:33 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 15:46:33 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:46:33 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 15:46:33 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:46:33 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:46:39 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAC47) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
10/06/2008 15:46:39 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
10/06/2008 15:46:39 SystemEvent The Application Experience Lookup service started successfully.
10/06/2008 15:47:13 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 15:47:13 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x1038D) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 15:47:13 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1038D) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 15:47:13 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 15:47:37 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1038d)
10/06/2008 15:47:37 SystemEvent The process Explorer.EXE has initiated the shutdown of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: shutdown Comment: j
10/06/2008 15:47:40 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1038D) Logon Type: 2
10/06/2008 15:47:43 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
10/06/2008 15:47:43 SystemEvent The Event log service was stopped.
10/06/2008 16:32:00 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/06/2008 16:32:00 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
10/06/2008 16:32:01 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
10/06/2008 16:32:12 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/06/2008 16:32:12 SystemEvent The Event log service was started.
10/06/2008 16:32:12 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
10/06/2008 16:32:16 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 16:32:16 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 16:32:16 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 16:32:16 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/06/2008 16:32:16 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
10/06/2008 16:32:22 SystemEvent The Application Experience Lookup service started successfully.
10/06/2008 16:32:22 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
10/06/2008 16:32:22 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA48F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
10/06/2008 16:33:02 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10391) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 16:33:02 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
10/06/2008 16:33:02 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
10/06/2008 16:33:02 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x10391) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
10/06/2008 16:33:17 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10391)
10/06/2008 16:33:17 SystemEvent The process Explorer.EXE has initiated the shutdown of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: shutdown Comment: g
10/06/2008 16:33:23 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10391) Logon Type: 2
10/06/2008 16:33:26 SystemEvent The Event log service was stopped.
10/06/2008 16:33:26 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
10/07/2008 08:43:17 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
10/07/2008 08:43:18 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
10/07/2008 08:43:18 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
10/07/2008 08:43:27 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
10/07/2008 08:43:27 SystemEvent The Event log service was started.
10/07/2008 08:43:28 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
10/07/2008 08:43:32 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: -
10/07/2008 08:43:32 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/07/2008 08:43:32 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
10/07/2008 08:43:32 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: -
10/07/2008 08:43:32 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
10/07/2008 08:43:41 SystemEvent The redirector was unable to register the address for transport NetBT_Tcpip_{691837B6-D398-4BBC-B05E for the following reason: . Transport has been taken offline.
10/07/2008 08:43:41 SystemEvent Application popup: Windows - System Error : A duplicate name exists on the network.
10/07/2008 08:43:41 SystemEvent The name "QMGSBC-DC1 :0" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.4 did not allow the name to be claimed by this machine.
10/07/2008 08:43:42 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA0A1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
10/07/2008 08:43:42 SystemEvent The name "QMGSBC-DC1 :20" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.4 did not allow the name to be claimed by this machine.
10/07/2008 08:43:42 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
10/07/2008 08:43:42 SystemEvent The server could not bind to the transport \Device\NetBT_Tcpip_{691837B6-D398-4BBC-B05E-62F1E1527CD8} because another computer on the network has the same name. The server could not start.
10/07/2008 08:43:42 SystemEvent The Application Experience Lookup service started successfully.
10/07/2008 08:44:15 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: IDE\DISKTOSHIBA_MK4019GAXB______________________FB002B__\34384A3437393331205420202020202020202020 Vetoing device: IDE\DiskTOSHIBA_MK4019GAXB______________________FB002B__\34384a3437393331205420202020202020202020 Vetoing service name: Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/07/2008 08:44:17 SystemEvent The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: STORAGE\VOLUME\1&30A96598&0&SIGNATUREB6F0B6F0OFFSET7E00LENGTH950A58200 Vetoing device: STORAGE\Volume\1&30a96598&0&SignatureB6F0B6F0Offset7E00Length950A58200 Vetoing service name: FileSystem\Ntfs Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer.
10/07/2008 08:45:10 SystemEvent The Terminal Services service entered the running state.
10/07/2008 08:45:10 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
10/07/2008 08:45:10 SystemEvent The Terminal Services service was successfully sent a start control.
10/07/2008 08:45:10 SystemEvent The Application Layer Gateway Service service entered the running state.
10/07/2008 08:45:10 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
10/07/2008 08:45:10 SystemEvent The Network Location Awareness (NLA) service entered the running state.
10/07/2008 09:43:10 SystemEvent The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent.
10/07/2008 12:00:00 SystemEvent The system uptime is 11811 seconds.
10/08/2008 08:43:42 SystemEvent The time service has not synchronized the system time for 86400 seconds because none of the time service providers provided a usable time stamp. The time service is no longer synchronized and cannot provide the time to other clients or update the system clock. Monitor the system events displayed in the Event Viewer to make sure that a more serious problem does not exist.
11/14/2008 15:27:53 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
11/14/2008 15:27:53 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
11/14/2008 15:27:53 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
11/14/2008 15:27:56 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: The network link is down. Check to make sure the network cable is properly connected.
11/14/2008 15:28:03 SystemEvent The system detected that network adapter Broadcom NetXtreme Gigabit Ethernet #2 was disconnected from the network, and the adapter's network configuration has been released. If the network adapter was not disconnected, this may indicate that it has malfunctioned. Please contact your vendor for updated drivers.
11/14/2008 15:28:03 SystemEvent The previous system shutdown at 15:42:27 on 09/10/2008 was unexpected.
11/14/2008 15:28:03 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
11/14/2008 15:28:03 SystemEvent The Event log service was started.
11/14/2008 15:28:04 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
11/14/2008 15:28:06 SystemEvent The Application Experience Lookup service started successfully.
11/14/2008 15:28:06 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
11/14/2008 15:28:07 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: -
11/14/2008 15:28:07 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
11/14/2008 15:28:07 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x9407) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/14/2008 15:28:07 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/14/2008 15:28:07 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: -
11/14/2008 15:28:07 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/14/2008 15:28:08 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
11/14/2008 15:28:13 SystemEvent The system detected that network adapter Broadcom NetXtreme Gigabit Ethernet #2 was connected to the network, and has initiated normal operation over the network adapter.
11/14/2008 15:29:16 SystemEvent Your computer has automatically configured the IP address for the Network Card with network address 000D609CD33D. The IP address being used is 169.254.68.89.
11/14/2008 15:29:16 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time.
11/14/2008 15:29:16 SystemEvent Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
11/14/2008 15:29:18 SystemEvent Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
11/14/2008 15:29:18 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time.
11/14/2008 15:29:20 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time.
11/14/2008 15:29:20 SystemEvent Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
11/14/2008 15:29:22 SystemEvent The server could not bind to the transport \Device\NetBT_Tcpip_{691837B6-D398-4BBC-B05E-62F1E1527CD8} because another computer on the network has the same name. The server could not start.
11/14/2008 15:29:22 SystemEvent The name "QMGSBC-DC1 :20" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.6 did not allow the name to be claimed by this machine.
11/14/2008 15:29:25 SystemEvent The name "QMGSBC-DC1 :0" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.6 did not allow the name to be claimed by this machine.
11/14/2008 15:29:25 SystemEvent The redirector was unable to register the address for transport NetBT_Tcpip_{691837B6-D398-4BBC-B05E for the following reason: . Transport has been taken offline.
11/14/2008 15:29:25 SystemEvent The name "QMGSBC-DC1 :20" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.6 did not allow the name to be claimed by this machine.
11/14/2008 15:29:25 SystemEvent The server could not bind to the transport \Device\NetBT_Tcpip_{691837B6-D398-4BBC-B05E-62F1E1527CD8} because another computer on the network has the same name. The server could not start.
11/14/2008 15:29:25 SystemEvent Application popup: Windows - System Error : A duplicate name exists on the network.
11/14/2008 15:29:51 SystemEvent The Network Location Awareness (NLA) service entered the running state.
11/14/2008 15:29:51 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
11/14/2008 15:29:51 SystemEvent The Terminal Services service was successfully sent a start control.
11/14/2008 15:29:51 SystemEvent The Application Layer Gateway Service service entered the running state.
11/14/2008 15:29:51 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
11/14/2008 15:29:51 SystemEvent The Terminal Services service entered the running state.
11/14/2008 16:27:45 SystemEvent The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent.
11/14/2008 21:58:16 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x30478) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/14/2008 21:58:24 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x30478) Logon Type: 3
11/15/2008 04:58:19 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x317F8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/15/2008 04:58:29 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x317F8) Logon Type: 3
11/15/2008 11:58:17 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x32964) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/15/2008 11:58:25 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x32964) Logon Type: 3
11/15/2008 12:00:00 SystemEvent The system uptime is 73936 seconds.
11/15/2008 15:28:06 SystemEvent The time service has not synchronized the system time for 86400 seconds because none of the time service providers provided a usable time stamp. The time service is no longer synchronized and cannot provide the time to other clients or update the system clock. Monitor the system events displayed in the Event Viewer to make sure that a more serious problem does not exist.
11/15/2008 18:58:20 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x38B2A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/15/2008 18:58:32 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x38B2A) Logon Type: 3
11/16/2008 01:58:19 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x39B3E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/16/2008 01:58:28 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x39B3E) Logon Type: 3
11/16/2008 08:58:22 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x3ACA5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/16/2008 08:58:31 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x3ACA5) Logon Type: 3
11/16/2008 12:00:00 SystemEvent The system uptime is 160336 seconds.
11/16/2008 15:58:23 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x40EC8) Logon Type: 3
11/16/2008 15:58:23 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x40EC8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/16/2008 22:58:25 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x42208) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/16/2008 22:58:31 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x42208) Logon Type: 3
11/17/2008 05:58:26 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x433F1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 05:58:35 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x433F1) Logon Type: 3
11/17/2008 09:08:11 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/17/2008 09:08:11 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 344 Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 09:08:11 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x4478D) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 344 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 09:08:11 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x4478D) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/17/2008 09:08:13 SystemEvent The reason supplied by user QMGSBC-DC1\Administrator for the last unexpected shutdown of this computer is: Other (Unplanned) Reason Code: 0xa000000 Bug ID: Bugcheck String: Comment: g
11/17/2008 09:08:25 SystemEvent The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: d
11/17/2008 09:08:26 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x4478d)
11/17/2008 09:08:27 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x4478D) Logon Type: 2
11/17/2008 09:08:30 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
11/17/2008 09:08:30 SystemEvent The Event log service was stopped.
11/17/2008 13:50:45 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
11/17/2008 13:50:46 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
11/17/2008 13:50:46 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
11/17/2008 13:50:56 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
11/17/2008 13:50:56 SystemEvent The Event log service was started.
11/17/2008 13:50:56 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
11/17/2008 13:51:01 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 13:51:01 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 13:51:01 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/17/2008 13:51:01 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/17/2008 13:51:01 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 13:51:07 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA6B1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/17/2008 13:51:07 SystemEvent The Application Experience Lookup service started successfully.
11/17/2008 13:51:07 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
11/17/2008 13:53:52 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
11/17/2008 13:53:53 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
11/17/2008 13:53:53 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
11/17/2008 13:54:06 SystemEvent The previous system shutdown at 13:50:56 on 17/11/2008 was unexpected.
11/17/2008 13:54:06 SystemEvent The Event log service was started.
11/17/2008 13:54:06 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
11/17/2008 13:54:07 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
11/17/2008 13:54:11 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 13:54:11 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/17/2008 13:54:11 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 13:54:11 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 13:54:11 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/17/2008 13:54:16 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAC5F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/17/2008 13:54:16 SystemEvent The Application Experience Lookup service started successfully.
11/17/2008 13:54:16 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
11/17/2008 13:55:45 SystemEvent The Application Layer Gateway Service service entered the running state.
11/17/2008 13:55:45 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
11/17/2008 13:55:45 SystemEvent The Network Location Awareness (NLA) service entered the running state.
11/17/2008 13:55:45 SystemEvent The Terminal Services service was successfully sent a start control.
11/17/2008 13:55:45 SystemEvent The Terminal Services service entered the running state.
11/17/2008 13:55:45 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
11/17/2008 13:56:48 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x15F0B) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/17/2008 13:56:48 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x15F0B) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 13:56:48 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 13:56:48 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/17/2008 13:56:50 SystemEvent The reason supplied by user QMGSBC-DC1\Administrator for the last unexpected shutdown of this computer is: Other (Unplanned) Reason Code: 0xa000000 Bug ID: d Bugcheck String: Comment: d
11/17/2008 14:12:10 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x220CE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 14:12:13 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x220CE) Logon Type: 3
11/17/2008 14:53:45 SystemEvent The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent.
11/17/2008 14:56:51 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x25A4F) Logon Type: 7
11/17/2008 14:56:51 SecurityEvent Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x25A4F) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/17/2008 14:56:51 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x25A4F) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 14:56:51 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 14:56:51 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/17/2008 14:58:49 SystemEvent Windows Server 2003 Hotfix KB925336 was installed.
11/17/2008 15:01:09 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x15f0b)
11/17/2008 15:01:09 SystemEvent The process winlogon.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Operating System: Hot fix (Planned) Reason Code: 0x80020011 Shutdown Type: restart Comment: Hotfix for Windows Server 2003 (KB925336)
11/17/2008 15:01:14 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
11/17/2008 15:01:14 SystemEvent The Event log service was stopped.
11/17/2008 15:02:39 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
11/17/2008 15:02:40 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
11/17/2008 15:02:40 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
11/17/2008 15:02:55 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
11/17/2008 15:02:55 SystemEvent The Event log service was started.
11/17/2008 15:02:55 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
11/17/2008 15:03:00 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:03:00 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/17/2008 15:03:00 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:03:00 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/17/2008 15:03:00 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:03:05 SystemEvent The Application Experience Lookup service started successfully.
11/17/2008 15:03:06 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAF93) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:03:06 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
11/17/2008 15:03:51 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/17/2008 15:03:51 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10416) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 15:03:51 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x10416) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/17/2008 15:03:51 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 15:04:34 SystemEvent The Network Location Awareness (NLA) service entered the running state.
11/17/2008 15:04:34 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
11/17/2008 15:04:34 SystemEvent The Terminal Services service was successfully sent a start control.
11/17/2008 15:04:34 SystemEvent The Application Layer Gateway Service service entered the running state.
11/17/2008 15:04:34 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
11/17/2008 15:04:34 SystemEvent The Terminal Services service entered the running state.
11/17/2008 15:09:07 SystemEvent The Windows Installer service was successfully sent a start control.
11/17/2008 15:09:07 SystemEvent The Windows Installer service entered the running state.
11/17/2008 15:11:52 SystemEvent The start type of the VMware Server Web Access service was changed from demand start to auto start.
11/17/2008 15:11:53 SystemEvent The VMware Server Web Access service was successfully sent a start control.
11/17/2008 15:11:55 SystemEvent The VMware Server Web Access service entered the running state.
11/17/2008 15:13:30 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x5FEDD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 15:13:31 SystemEvent The VMware Bridge Protocol service was successfully sent a start control.
11/17/2008 15:13:35 SystemEvent The description for Event ID ( 00001 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event:
11/17/2008 15:13:35 SystemEvent The description for Event ID ( 00004 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: \Device\VMnetUserif0
11/17/2008 15:13:36 SystemEvent The VMware NAT Service service entered the running state.
11/17/2008 15:13:36 SystemEvent The VMware NAT Service service was successfully sent a start control.
11/17/2008 15:13:37 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x5FEDD) Logon Type: 3
11/17/2008 15:13:40 SystemEvent The VMware DHCP Service service was successfully sent a start control.
11/17/2008 15:13:40 SystemEvent The VMware DHCP Service service entered the running state.
11/17/2008 15:13:46 SystemEvent The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Starting up: 0x8957faf0, \REGISTRY\MACHINE\SYSTEM\Contr
11/17/2008 15:13:46 SystemEvent The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Driver entry successful.
11/17/2008 15:13:47 SystemEvent The Remote Access Connection Manager service was successfully sent a start control.
11/17/2008 15:13:47 SystemEvent The Telephony service entered the running state.
11/17/2008 15:13:48 SystemEvent The Remote Access Connection Manager service entered the running state.
11/17/2008 15:13:49 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time.
11/17/2008 15:13:49 SystemEvent The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.
11/17/2008 15:13:49 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time.
11/17/2008 15:13:58 SystemEvent The server could not bind to the transport \Device\NetBT_Tcpip_{29C4D1CD-1997-4A46-969F-AE522B22DAFE}.
11/17/2008 15:14:09 SystemEvent The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.
11/17/2008 15:14:10 SystemEvent The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.
11/17/2008 15:14:13 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time.
11/17/2008 15:14:15 SystemEvent The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time.
11/17/2008 15:14:24 SystemEvent The VMware vmx86 service was successfully sent a start control.
11/17/2008 15:14:25 SystemEvent The VMware hcmon service was successfully sent a start control.
11/17/2008 15:14:30 SecurityEvent Successful Logon: User Name: __vmware_user__ Domain: QMGSBC-DC1 Logon ID: (0x0,0x74EE2) Logon Type: 2 Logon Process: Advapi Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 2704 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:14:30 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: __vmware_user__ Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/17/2008 15:14:30 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: __vmware_user__ Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 2704 Source Network Address: - Source Port: -
11/17/2008 15:14:31 SystemEvent The VMware Authorization Service service entered the running state.
11/17/2008 15:14:31 SystemEvent The VMware Authorization Service service was successfully sent a start control.
11/17/2008 15:14:32 SystemEvent The VMware vmci service was successfully sent a start control.
11/17/2008 15:14:54 SystemEvent The VMware Host Agent service was successfully sent a start control.
11/17/2008 15:14:54 SystemEvent The VMware Host Agent service entered the running state.
11/17/2008 15:15:20 SystemEvent The process msiexec.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found Reason Code: 0x80030002 Shutdown Type: restart Comment: The Windows Installer initiated a system restart to complete or continue the configuration of 'VMware Server'.
11/17/2008 15:15:21 SystemEvent The Windows Installer service entered the stopped state.
11/17/2008 15:15:21 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10416)
11/17/2008 15:15:31 SystemEvent The Event log service was stopped.
11/17/2008 15:15:31 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
11/17/2008 15:17:02 SystemEvent The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Starting up: 0x899f3720, \REGISTRY\MACHINE\SYSTEM\Contr
11/17/2008 15:17:02 SystemEvent The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Driver entry successful.
11/17/2008 15:17:03 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
11/17/2008 15:17:03 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
11/17/2008 15:17:04 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
11/17/2008 15:17:18 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
11/17/2008 15:17:18 SystemEvent The Event log service was started.
11/17/2008 15:17:18 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
11/17/2008 15:17:23 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:17:23 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/17/2008 15:17:23 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:17:23 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/17/2008 15:17:23 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:17:32 SystemEvent The Application Experience Lookup service started successfully.
11/17/2008 15:17:32 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
11/17/2008 15:17:33 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB981) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:17:42 SystemEvent The description for Event ID ( 00001 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event:
11/17/2008 15:17:42 SystemEvent The description for Event ID ( 00004 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: \Device\VMnetUserif0
11/17/2008 15:17:46 SecurityEvent Successful Logon: User Name: __vmware_user__ Domain: QMGSBC-DC1 Logon ID: (0x0,0xFFFF) Logon Type: 2 Logon Process: Advapi Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 1472 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:17:46 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: __vmware_user__ Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 1472 Source Network Address: - Source Port: -
11/17/2008 15:17:46 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: __vmware_user__ Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/17/2008 15:18:35 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 15:18:35 SecurityEvent Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/17/2008 15:18:35 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
11/17/2008 15:18:35 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/17/2008 15:18:53 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
11/17/2008 15:18:53 SystemEvent The Terminal Services service entered the running state.
11/17/2008 15:18:53 SystemEvent The Network Location Awareness (NLA) service entered the running state.
11/17/2008 15:18:53 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
11/17/2008 15:18:53 SystemEvent The Terminal Services service was successfully sent a start control.
11/17/2008 15:18:53 SystemEvent The Application Layer Gateway Service service entered the running state.
11/17/2008 15:23:37 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 1528 Source Network Address: - Source Port: -
11/17/2008 15:23:37 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/17/2008 15:23:37 SecurityEvent Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x35B7F) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/17/2008 15:23:37 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x35B7F) Logon Type: 2 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 1528 Transited Services: - Source Network Address: - Source Port: -
11/17/2008 15:25:24 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x3B7CA) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 15:25:24 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x3B7CA) Logon Type: 3
11/17/2008 15:34:27 SystemEvent The Windows Installer service entered the running state.
11/17/2008 15:34:27 SystemEvent The Windows Installer service was successfully sent a start control.
11/17/2008 15:40:37 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x59134) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 15:40:42 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x59134) Logon Type: 3
11/17/2008 15:55:55 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x6E7FB) Logon Type: 3
11/17/2008 15:55:55 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x6E7FB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 15:58:07 SystemEvent The Windows Installer service entered the stopped state.
11/17/2008 15:59:35 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x35B7F) Logon Type: 2
11/17/2008 16:04:22 SystemEvent The master browser has received a server announcement from the computer PC2-2 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{691837B6-D398-4BBC-B05. The master browser is stopping or an election is being forced.
11/17/2008 16:12:01 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x71C26) Logon Type: 3
11/17/2008 16:12:01 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x71C26) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 16:16:53 SystemEvent The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent.
11/17/2008 16:18:15 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x72FE8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 16:18:22 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x72FE8) Logon Type: 3
11/17/2008 16:25:21 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x7970E) Logon Type: 3
11/17/2008 16:25:21 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x7970E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 16:40:24 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x7C027) Logon Type: 3
11/17/2008 16:40:24 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x7C027) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 16:55:37 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x7EC3F) Logon Type: 3
11/17/2008 16:55:37 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x7EC3F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 17:10:38 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x815FC) Logon Type: 3
11/17/2008 17:10:38 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x815FC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 17:21:15 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x8330C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 17:21:23 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x8330C) Logon Type: 3
11/17/2008 17:25:25 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x83E9C) Logon Type: 3
11/17/2008 17:25:25 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x83E9C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 17:40:24 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x867C0) Logon Type: 3
11/17/2008 17:40:24 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x867C0) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 17:55:37 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x890EF) Logon Type: 3
11/17/2008 17:55:37 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x890EF) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 18:10:43 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x8BA33) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 18:10:44 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x8BA33) Logon Type: 3
11/17/2008 18:21:32 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x8D77E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 18:21:35 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x8D77E) Logon Type: 3
11/17/2008 18:25:25 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x8E3CB) Logon Type: 3
11/17/2008 18:25:25 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x8E3CB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 18:40:26 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x90C88) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 18:40:26 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x90C88) Logon Type: 3
11/17/2008 18:55:53 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x936B3) Logon Type: 3
11/17/2008 18:55:53 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x936B3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 19:10:27 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x95E49) Logon Type: 3
11/17/2008 19:10:27 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x95E49) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 19:22:00 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x97D8D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 19:22:09 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x97D8D) Logon Type: 3
11/17/2008 19:25:28 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x98733) Logon Type: 3
11/17/2008 19:25:28 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x98733) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 19:40:28 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x9AFD5) Logon Type: 3
11/17/2008 19:40:28 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x9AFD5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 19:55:52 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x9D985) Logon Type: 3
11/17/2008 19:55:52 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x9D985) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 19:58:31 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x9E0AB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 19:58:34 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x9E0AB) Logon Type: 3
11/17/2008 20:10:29 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA0131) Logon Type: 3
11/17/2008 20:10:29 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA0131) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 20:22:19 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA22F8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 20:22:30 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA22F8) Logon Type: 3
11/17/2008 20:25:29 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA2BB9) Logon Type: 3
11/17/2008 20:25:29 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA2BB9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 20:40:30 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA54AB) Logon Type: 3
11/17/2008 20:40:30 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA54AB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 20:55:52 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA7E65) Logon Type: 3
11/17/2008 20:55:52 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA7E65) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 21:10:38 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xAA647) Logon Type: 3
11/17/2008 21:10:38 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAA647) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 21:22:11 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAC826) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 21:22:15 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xAC826) Logon Type: 3
11/17/2008 21:25:31 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xAD158) Logon Type: 3
11/17/2008 21:25:31 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAD158) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 21:40:32 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xAF9E8) Logon Type: 3
11/17/2008 21:40:32 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAF9E8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 21:55:57 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB2569) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 21:55:57 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB2569) Logon Type: 3
11/17/2008 22:10:33 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB4D60) Logon Type: 3
11/17/2008 22:10:33 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB4D60) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 22:21:38 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB6B77) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 22:21:43 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB6B77) Logon Type: 3
11/17/2008 22:25:33 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB761C) Logon Type: 3
11/17/2008 22:25:33 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB761C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 22:40:33 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB9EAC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 22:40:33 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB9EAC) Logon Type: 3
11/17/2008 22:55:57 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xBC866) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 22:55:57 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xBC866) Logon Type: 3
11/17/2008 23:10:46 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xBF087) Logon Type: 3
11/17/2008 23:10:46 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xBF087) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 23:21:57 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC0EDB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 23:22:08 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC0EDB) Logon Type: 3
11/17/2008 23:25:35 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC18B8) Logon Type: 3
11/17/2008 23:25:35 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC18B8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 23:40:36 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC432E) Logon Type: 3
11/17/2008 23:40:36 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC432E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/17/2008 23:55:59 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC6D47) Logon Type: 3
11/17/2008 23:55:59 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC6D47) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 00:10:44 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC95BA) Logon Type: 3
11/18/2008 00:10:44 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC95BA) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 00:22:06 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xCB493) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 00:22:16 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xCB493) Logon Type: 3
11/18/2008 00:25:38 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xCBE21) Logon Type: 3
11/18/2008 00:25:38 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xCBE21) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 00:40:38 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xCE6BA) Logon Type: 3
11/18/2008 00:40:38 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xCE6BA) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 00:56:01 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD10A5) Logon Type: 3
11/18/2008 00:56:01 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD10A5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 01:10:44 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD3A20) Logon Type: 3
11/18/2008 01:10:44 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD3A20) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 01:21:57 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD58D1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 01:22:02 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD58D1) Logon Type: 3
11/18/2008 01:25:40 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD62E6) Logon Type: 3
11/18/2008 01:25:40 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD62E6) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 01:40:40 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD8B80) Logon Type: 3
11/18/2008 01:40:40 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD8B80) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 01:56:06 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xDB587) Logon Type: 3
11/18/2008 01:56:06 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xDB587) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 02:10:48 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xDDD59) Logon Type: 3
11/18/2008 02:10:48 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xDDD59) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 02:22:06 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xDFC05) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 02:22:10 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xDFC05) Logon Type: 3
11/18/2008 02:25:42 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE05E5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 02:25:42 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE05E5) Logon Type: 3
11/18/2008 02:40:42 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE2E7E) Logon Type: 3
11/18/2008 02:40:42 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE2E7E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 02:56:02 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE5810) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 02:56:02 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE5810) Logon Type: 3
11/18/2008 02:58:31 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE5EA4) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 02:58:35 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE5EA4) Logon Type: 3
11/18/2008 03:10:42 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE820B) Logon Type: 3
11/18/2008 03:10:42 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE820B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 03:22:11 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xEA3B7) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 03:22:13 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xEA3B7) Logon Type: 3
11/18/2008 03:25:43 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xEAD7F) Logon Type: 3
11/18/2008 03:25:43 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xEAD7F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 03:40:43 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xED61B) Logon Type: 3
11/18/2008 03:40:43 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xED61B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 03:56:13 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xEFFFE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 03:56:13 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xEFFFE) Logon Type: 3
11/18/2008 04:10:55 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xF27B4) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 04:10:55 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xF27B4) Logon Type: 3
11/18/2008 04:21:50 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xF4573) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 04:21:59 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xF4573) Logon Type: 3
11/18/2008 04:25:44 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xF501D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 04:25:44 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xF501D) Logon Type: 3
11/18/2008 04:40:45 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xF7B1E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 04:40:45 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xF7B1E) Logon Type: 3
11/18/2008 04:56:07 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xFA537) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 04:56:07 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xFA537) Logon Type: 3
11/18/2008 05:10:46 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xFCCE5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 05:10:46 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xFCCE5) Logon Type: 3
11/18/2008 05:22:15 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xFEBE3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 05:22:16 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xFEBE3) Logon Type: 3
11/18/2008 05:25:47 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xFF5A9) Logon Type: 3
11/18/2008 05:25:47 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xFF5A9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 05:40:47 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x101E41) Logon Type: 3
11/18/2008 05:40:47 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x101E41) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 05:56:08 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1047F3) Logon Type: 3
11/18/2008 05:56:08 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1047F3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 06:10:53 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x106FBD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 06:10:53 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x106FBD) Logon Type: 3
11/18/2008 06:21:54 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x108DC5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 06:21:56 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x108DC5) Logon Type: 3
11/18/2008 06:25:49 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x109AFD) Logon Type: 3
11/18/2008 06:25:49 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x109AFD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 06:40:50 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x10C3C6) Logon Type: 3
11/18/2008 06:40:50 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x10C3C6) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 06:56:19 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x10EE6B) Logon Type: 3
11/18/2008 06:56:19 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x10EE6B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 07:11:06 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1116C7) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 07:11:06 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1116C7) Logon Type: 3
11/18/2008 07:21:05 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x113204) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 07:21:14 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x113204) Logon Type: 3
11/18/2008 07:25:54 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x113F21) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 07:25:54 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x113F21) Logon Type: 3
11/18/2008 07:40:55 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1167E4) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 07:40:55 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1167E4) Logon Type: 3
11/18/2008 07:56:25 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x119241) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 07:56:25 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x119241) Logon Type: 3
11/18/2008 08:11:01 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x11BBB2) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 08:11:01 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x11BBB2) Logon Type: 3
11/18/2008 08:20:01 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x11D432) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 08:20:05 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x11D432) Logon Type: 3
11/18/2008 08:25:57 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x11E426) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 08:25:57 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x11E426) Logon Type: 3
11/18/2008 08:40:55 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x120D20) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 08:40:55 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x120D20) Logon Type: 3
11/18/2008 08:56:16 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1236FE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 08:56:16 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1236FE) Logon Type: 3
11/18/2008 09:11:00 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x125F01) Logon Type: 3
11/18/2008 09:11:00 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x125F01) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 09:14:03 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x126799) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 09:14:05 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x126799) Logon Type: 3
11/18/2008 09:25:56 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x128A68) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 09:25:56 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x128A68) Logon Type: 3
11/18/2008 09:40:57 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x12B37C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 09:40:57 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x12B37C) Logon Type: 3
11/18/2008 09:56:05 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x12DED1) Logon Type: 3
11/18/2008 09:56:05 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x12DED1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 09:58:10 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x12E499) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 09:58:14 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x12E499) Logon Type: 3
11/18/2008 10:10:59 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x130794) Logon Type: 3
11/18/2008 10:10:59 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x130794) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 10:13:24 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x130E55) Logon Type: 3
11/18/2008 10:13:24 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x130E55) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 10:25:59 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x133094) Logon Type: 3
11/18/2008 10:25:59 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x133094) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 10:41:00 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1359E1) Logon Type: 3
11/18/2008 10:41:00 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1359E1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 10:56:10 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x13834A) Logon Type: 3
11/18/2008 10:56:10 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x13834A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 11:11:01 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x13ABC3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 11:11:01 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x13ABC3) Logon Type: 3
11/18/2008 11:13:47 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x13B358) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 11:13:48 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x13B358) Logon Type: 3
11/18/2008 11:26:34 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x13D603) Logon Type: 3
11/18/2008 11:26:34 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x13D603) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 11:41:34 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x14009C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 11:41:34 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x14009C) Logon Type: 3
11/18/2008 11:56:22 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1428F5) Logon Type: 3
11/18/2008 11:56:22 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1428F5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 12:00:00 SystemEvent The system uptime is 74588 seconds.
11/18/2008 12:09:58 SystemEvent The master browser has received a server announcement from the computer PC2-2 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{691837B6-D398-4BBC-B05. The master browser is stopping or an election is being forced.
11/18/2008 12:13:26 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x14572D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 12:13:27 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x14572D) Logon Type: 3
11/18/2008 13:14:21 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x14FC7B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 13:14:30 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x14FC7B) Logon Type: 3
11/18/2008 14:14:20 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x15A020) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 14:14:26 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x15A020) Logon Type: 3
11/18/2008 14:26:09 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x15C122) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 14:26:09 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x15C122) Logon Type: 3
11/18/2008 14:41:12 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x15E9E9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 14:41:12 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x15E9E9) Logon Type: 3
11/18/2008 14:56:46 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x16148E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 14:56:46 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x16148E) Logon Type: 3
11/18/2008 15:11:13 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x163D93) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 15:11:13 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x163D93) Logon Type: 3
11/18/2008 15:15:11 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x16484B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 15:15:16 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x16484B) Logon Type: 3
11/18/2008 15:17:42 SystemEvent The time service has not synchronized the system time for 86400 seconds because none of the time service providers provided a usable time stamp. The time service is no longer synchronized and cannot provide the time to other clients or update the system clock. Monitor the system events displayed in the Event Viewer to make sure that a more serious problem does not exist.
11/18/2008 15:26:11 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x166BB9) Logon Type: 3
11/18/2008 15:26:11 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x166BB9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 15:41:11 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x169470) Logon Type: 3
11/18/2008 15:41:11 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x169470) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 15:52:48 SystemEvent The master browser has received a server announcement from the computer PC2-2 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{691837B6-D398-4BBC-B05. The master browser is stopping or an election is being forced.
11/18/2008 16:18:22 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x16F9BF) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 16:18:34 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x16F9BF) Logon Type: 3
11/18/2008 16:58:26 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x17AF1F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 16:58:30 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x17AF1F) Logon Type: 3
11/18/2008 17:22:23 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x17F1B7) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 17:22:32 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x17F1B7) Logon Type: 3
11/18/2008 17:38:42 SystemEvent The name "WORKGROUP :1d" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.5.165 did not allow the name to be claimed by this machine.
11/18/2008 17:49:01 SystemEvent The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is unknown.
11/18/2008 18:22:26 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1894F6) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 18:22:31 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1894F6) Logon Type: 3
11/18/2008 18:41:47 SystemEvent The browser was unable to promote itself to master browser. The browser will continue to attempt to promote itself to the master browser, but will no longer log any events in the event log in Event Viewer.
11/18/2008 19:23:08 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x193B02) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 19:23:12 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x193B02) Logon Type: 3
11/18/2008 20:23:46 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x19DF99) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 20:23:50 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x19DF99) Logon Type: 3
11/18/2008 21:23:33 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1A85A5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 21:23:36 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1A85A5) Logon Type: 3
11/18/2008 22:24:07 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1B2BCC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 22:24:11 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1B2BCC) Logon Type: 3
11/18/2008 23:24:07 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1BCE23) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 23:24:10 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1BCE23) Logon Type: 3
11/18/2008 23:58:30 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1C2BA3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/18/2008 23:58:32 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1C2BA3) Logon Type: 3
11/19/2008 00:24:14 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1C7368) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 00:24:17 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1C7368) Logon Type: 3
11/19/2008 01:23:34 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1D13FE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 01:23:36 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1D13FE) Logon Type: 3
11/19/2008 02:23:25 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1DB847) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 02:23:30 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1DB847) Logon Type: 3
11/19/2008 03:23:59 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1E5EA0) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 03:24:01 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1E5EA0) Logon Type: 3
11/19/2008 04:23:45 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1F02A1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 04:23:57 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1F02A1) Logon Type: 3
11/19/2008 05:23:18 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1FA3FB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 05:23:24 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1FA3FB) Logon Type: 3
11/19/2008 06:23:56 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x2049D5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 06:24:00 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x2049D5) Logon Type: 3
11/19/2008 06:58:31 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x20A79B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 06:58:33 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x20A79B) Logon Type: 3
11/19/2008 07:21:47 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x20E8DD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 07:21:51 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x20E8DD) Logon Type: 3
11/19/2008 08:17:08 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x217EAC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 08:17:13 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x217EAC) Logon Type: 3
11/19/2008 09:13:03 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x221860) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 09:13:10 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x221860) Logon Type: 3
11/19/2008 10:13:24 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x22BE59) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 10:13:33 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x22BE59) Logon Type: 3
11/19/2008 10:56:45 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/19/2008 10:56:46 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
11/19/2008 10:56:46 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x2343B1) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
11/19/2008 10:56:46 SecurityEvent Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x2343B1) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 10:56:46 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x2343B1) Logon Type: 7
11/19/2008 10:56:54 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/19/2008 10:56:54 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 1528 Source Network Address: - Source Port: -
11/19/2008 10:56:54 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x23461D) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 10:56:54 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x23461D) Logon Type: 2 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 1528 Transited Services: - Source Network Address: - Source Port: -
11/19/2008 11:13:09 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x24B4BC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 11:13:18 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x24B4BC) Logon Type: 3
11/19/2008 11:29:51 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x260F89) Logon Type: 7
11/19/2008 11:29:51 SecurityEvent Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x260F89) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 11:29:51 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x260F89) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
11/19/2008 11:29:51 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0
11/19/2008 11:29:51 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0
11/19/2008 11:31:10 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {6d13d746-7791-45fb-be8a-ffb1b539be0d} Target Server Name: QMGSDC1 Target Server Info: cifs/QMGSDC1 Caller Process ID: 408 Source Network Address: - Source Port: -
11/19/2008 11:31:26 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {fbb88fc6-5a45-ddef-9d4e-eaaad627f0fd} Target Server Name: QMGSDC1 Target Server Info: cifs/QMGSDC1 Caller Process ID: 408 Source Network Address: - Source Port: -
11/19/2008 11:31:30 SystemEvent The Net Logon service entered the running state.
11/19/2008 11:31:30 SystemEvent The start type of the Net Logon service was changed from demand start to auto start.
11/19/2008 11:31:30 SystemEvent The Net Logon service was successfully sent a start control.
11/19/2008 11:31:31 SystemEvent This computer has been successfully joined to domain 'qmgs'.
11/19/2008 11:31:51 SystemEvent Attempt to update DNS Host Name of the computer object in Active Directory failed. The updated value was 'qmgsbc-dc1'. The following error occurred: The parameter is incorrect.
11/19/2008 11:31:51 SystemEvent Attempt to update HOST Service Principal Names (SPNs) of the computer object in Active Directory failed. The updated values were 'HOST/qmgsbc-dc1' and 'HOST/QMGSBC-DC1'. The following error occurred: The parameter is incorrect.
11/19/2008 11:32:00 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {b9907fa1-8773-d424-9d81-423b76d9fb1f} Target Server Name: QMGSDC1 Target Server Info: cifs/QMGSDC1 Caller Process ID: 408 Source Network Address: - Source Port: -
11/19/2008 11:32:00 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {b9907fa1-8773-d424-9d81-423b76d9fb1f} Target Server Name: QMGSDC1.qmgs.internal Target Server Info: ldap/QMGSDC1.qmgs.internal Caller Process ID: 408 Source Network Address: - Source Port: -
11/19/2008 11:32:01 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {b9907fa1-8773-d424-9d81-423b76d9fb1f} Target Server Name: QMGSDC1 Target Server Info: LDAP/QMGSDC1 Caller Process ID: 408 Source Network Address: - Source Port: -
11/19/2008 11:32:23 SystemEvent The process rundll32.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: No title for this reason could be found Reason Code: 0x80050004 Shutdown Type: restart Comment:
11/19/2008 11:32:23 SecurityEvent User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1b915)
11/19/2008 11:32:33 SystemEvent The VMware Host Agent service entered the stopped state.
11/19/2008 11:32:36 SecurityEvent User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x23461D) Logon Type: 2
11/19/2008 11:32:47 SecurityEvent Windows is shutting down. All logon sessions will be terminated by this shutdown.
11/19/2008 11:32:47 SystemEvent The Event log service was stopped.
11/19/2008 11:34:20 SystemEvent The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Driver entry successful.
11/19/2008 11:34:20 SystemEvent The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Starting up: 0x89ba7030, \REGISTRY\MACHINE\SYSTEM\Contr
11/19/2008 11:34:21 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully.
11/19/2008 11:34:22 SystemEvent Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link.
11/19/2008 11:34:22 SystemEvent The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start.
11/19/2008 11:34:39 SystemEvent The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.
11/19/2008 11:34:39 SystemEvent The Event log service was started.
11/19/2008 11:34:39 SystemEvent Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free.
11/19/2008 11:34:39 SystemEvent The NetBIOS name and DNS host name of this machine have been changed from QMGSBC-DC1 to QMGSBC-VM2.
11/19/2008 11:34:43 SecurityEvent Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-VM2$ Caller Domain: QMGS Caller Logon ID: (0x0,0x3E7) Caller Process ID: 400 Transited Services: - Source Network Address: - Source Port: -
11/19/2008 11:34:43 SecurityEvent Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/19/2008 11:34:43 SecurityEvent Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-VM2$ Caller Domain: QMGS Caller Logon ID: (0x0,0x3E7) Caller Process ID: 400 Transited Services: - Source Network Address: - Source Port: -
11/19/2008 11:34:43 SecurityEvent Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: -
11/19/2008 11:34:43 SecurityEvent Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege
11/19/2008 11:34:53 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB3D4) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/19/2008 11:34:53 SystemEvent The Application Experience Lookup service started successfully.
11/19/2008 11:34:53 SystemEvent The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer.
11/19/2008 11:34:53 SystemEvent The description for Event ID ( 00001 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event:
11/19/2008 11:34:53 SystemEvent The description for Event ID ( 00004 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: \Device\VMnetUserif0
11/19/2008 11:35:09 SecurityEvent Successful Logon: User Name: __vmware_user__ Domain: QMGSBC-VM2 Logon ID: (0x0,0xCC4E) Logon Type: 2 Logon Process: Advapi Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Workstation Name: QMGSBC-VM2 Logon GUID: - Caller User Name: QMGSBC-VM2$ Caller Domain: QMGS Caller Logon ID: (0x0,0x3E7) Caller Process ID: 1440 Transited Services: - Source Network Address: - Source Port: -
11/19/2008 11:35:09 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: __vmware_user__ Target Domain: QMGSBC-VM2 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 1440 Source Network Address: - Source Port: -
11/19/2008 11:35:09 SecurityEvent Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: __vmware_user__ Source Workstation: QMGSBC-VM2 Error Code: 0x0
11/19/2008 11:35:09 SystemEvent The time provider NtpClient is currently receiving valid time data from qmgsdc1.QMGS.internal (ntp.d|192.168.5.1:123->192.168.0.1:123).
11/19/2008 12:30:21 SystemEvent The time service is now synchronizing the system time with the time source qmgsdc1.QMGS.internal (ntp.d|192.168.5.1:123->192.168.0.1:123).
11/19/2008 12:31:11 SecurityEvent Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x1C2AF) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 12:31:11 SecurityEvent Successful Logon: User Name: Administrator Domain: QMGS Logon ID: (0x0,0x1C2AF) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-VM2 Logon GUID: {212b45e1-0314-0767-6733-ac03a8198538} Caller User Name: QMGSBC-VM2$ Caller Domain: QMGS Caller Logon ID: (0x0,0x3E7) Caller Process ID: 352 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0
11/19/2008 12:31:11 SecurityEvent Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGS Target Logon GUID: {212b45e1-0314-0767-6733-ac03a8198538} Target Server Name: localhost Target Server Info: localhost Caller Process ID: 352 Source Network Address: 127.0.0.1 Source Port: 0
11/19/2008 12:31:13 SystemEvent The Network Location Awareness (NLA) service was successfully sent a start control.
11/19/2008 12:31:13 SystemEvent The Network Location Awareness (NLA) service entered the running state.
11/19/2008 12:31:13 SystemEvent The Terminal Services service entered the running state.
11/19/2008 12:31:13 SystemEvent The Application Layer Gateway Service service was successfully sent a start control.
11/19/2008 12:31:13 SystemEvent The Application Layer Gateway Service service entered the running state.
11/19/2008 12:31:13 SystemEvent The Terminal Services service was successfully sent a start control.
11/19/2008 12:31:15 SystemEvent The Telephony service entered the running state.
11/19/2008 12:31:15 SystemEvent The Remote Access Connection Manager service was successfully sent a start control.
11/19/2008 12:31:15 SystemEvent The Remote Access Connection Manager service entered the running state.
11/19/2008 12:31:35 SystemEvent The Windows Installer service was successfully sent a start control.
11/19/2008 12:31:35 SystemEvent The Windows Installer service entered the running state.
11/19/2008 12:32:26 SystemEvent The WinHTTP Web Proxy Auto-Discovery Service service was successfully sent a start control.
11/19/2008 12:32:26 SystemEvent The WinHTTP Web Proxy Auto-Discovery Service service entered the running state.
11/19/2008 12:41:36 SystemEvent The Windows Installer service entered the stopped state.
11/19/2008 12:48:56 SystemEvent The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.
11/19/2008 12:48:56 SystemEvent The WinHTTP Web Proxy Auto-Discovery Service service entered the stopped state.
11/19/2008 12:48:56 SystemEvent The WinHTTP Web Proxy Auto-Discovery Service suspended operation.
11/19/2008 12:55:03 SystemEvent The system uptime is 1551 seconds.
11/19/2008 13:08:33 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x490D8) Logon Type: 3
11/19/2008 13:08:33 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x490D8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:08:33 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x490C7) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:08:33 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x490C7) Logon Type: 3
11/19/2008 13:09:56 SecurityEvent Successful Network Logon: User Name: QMGSAV1$ Domain: QMGS Logon ID: (0x0,0x49492) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {6778f910-c28e-b6b2-a16d-924523e72afc} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:10:08 SecurityEvent User Logoff: User Name: QMGSAV1$ Domain: QMGS Logon ID: (0x0,0x49492) Logon Type: 3
11/19/2008 13:21:47 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4B6AC) Logon Type: 3
11/19/2008 13:21:47 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4B6AC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:21:48 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4B6D9) Logon Type: 3
11/19/2008 13:21:48 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4B6D9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:21:52 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4B6EC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:21:52 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4B6F8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:21:52 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4B6F8) Logon Type: 3
11/19/2008 13:21:52 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4B6EC) Logon Type: 3
11/19/2008 13:29:13 SystemEvent The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent.
11/19/2008 13:36:47 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4E15A) Logon Type: 3
11/19/2008 13:36:47 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4E15A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:36:48 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4E187) Logon Type: 3
11/19/2008 13:36:48 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4E187) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:36:53 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4E1B2) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:36:53 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4E1B2) Logon Type: 3
11/19/2008 13:36:53 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4E1BE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:36:53 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4E1BE) Logon Type: 3
11/19/2008 13:51:48 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x50C27) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:51:48 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x50C27) Logon Type: 3
11/19/2008 13:51:49 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x50C36) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:51:49 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x50C36) Logon Type: 3
11/19/2008 13:52:10 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x50D2A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:52:10 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x50D2A) Logon Type: 3
11/19/2008 13:52:10 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x50D36) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 13:52:10 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x50D36) Logon Type: 3
11/19/2008 14:06:48 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x536D0) Logon Type: 3
11/19/2008 14:06:48 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x536D0) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 14:06:49 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x536DF) Logon Type: 3
11/19/2008 14:06:49 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x536DF) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 14:07:21 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x538A0) Logon Type: 3
11/19/2008 14:07:21 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x538A0) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 14:07:21 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x53892) Logon Type: 3
11/19/2008 14:07:21 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x53892) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 14:10:47 SecurityEvent Successful Network Logon: User Name: QMGSAV1$ Domain: QMGS Logon ID: (0x0,0x5442E) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {6778f910-c28e-b6b2-a16d-924523e72afc} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 14:10:48 SecurityEvent User Logoff: User Name: QMGSAV1$ Domain: QMGS Logon ID: (0x0,0x5442E) Logon Type: 3
11/19/2008 14:21:49 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x563FB) Logon Type: 3
11/19/2008 14:21:49 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x563FB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 14:21:50 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x5640A) Logon Type: 3
11/19/2008 14:21:50 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x5640A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 14:21:54 SecurityEvent Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x5644E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0
11/19/2008 14:21:54 SecurityEvent User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x5644E) Logon Type: 3
11/19/2008 14:23:16 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x568A3) Logon Type: 3
11/19/2008 14:23:16 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x568A3) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/19/2008 14:23:16 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x568A3) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 16:06:33 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x6B82B) Logon Type: 3
11/19/2008 16:06:33 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x6B82B) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/19/2008 16:06:33 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x6B82B) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 17:40:33 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x81405) Logon Type: 3
11/19/2008 17:40:33 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x81405) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 17:40:33 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x81405) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/19/2008 19:31:33 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x95588) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 19:31:33 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x95588) Logon Type: 3
11/19/2008 19:31:33 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x95588) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/19/2008 21:09:33 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xA7588) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/19/2008 21:09:33 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xA7588) Logon Type: 3
11/19/2008 21:09:33 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xA7588) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/19/2008 22:49:47 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xB97A1) Logon Type: 3
11/19/2008 22:49:47 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xB97A1) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/19/2008 22:49:47 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xB97A1) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 00:21:53 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xCA2AB) Logon Type: 3
11/20/2008 00:21:53 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xCA2AB) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 00:21:53 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xCA2AB) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 02:15:07 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xDE907) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 02:15:07 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xDE907) Logon Type: 3
11/20/2008 02:15:07 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xDE907) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 03:48:21 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xEF678) Logon Type: 3
11/20/2008 03:48:21 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xEF678) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 03:48:21 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xEF678) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 05:32:21 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x102A1C) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 05:32:21 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x102A1C) Logon Type: 3
11/20/2008 05:32:21 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x102A1C) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 07:03:34 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1132D6) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 07:03:34 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1132D6) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 07:03:35 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1132D6) Logon Type: 3
11/20/2008 08:34:49 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x123FB6) Logon Type: 3
11/20/2008 08:34:49 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x123FB6) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 08:34:49 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x123FB6) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 10:31:03 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x138E01) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 10:31:03 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x138E01) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 10:31:03 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x138E01) Logon Type: 3
11/20/2008 12:00:00 SystemEvent The system uptime is 84648 seconds.
11/20/2008 12:07:17 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x14A373) Logon Type: 3
11/20/2008 12:07:17 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x14A373) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 12:07:17 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x14A373) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 13:53:30 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x15E20E) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 13:53:30 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x15E20E) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 13:53:31 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x15E20E) Logon Type: 3
11/20/2008 15:49:30 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1731DB) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 15:49:30 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1731DB) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 15:49:30 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1731DB) Logon Type: 3
11/20/2008 17:32:44 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x185BF7) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 17:32:44 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x185BF7) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 17:32:44 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x185BF7) Logon Type: 3
11/20/2008 19:06:44 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x19B7CD) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 19:06:44 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x19B7CD) Logon Type: 3
11/20/2008 19:06:44 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x19B7CD) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 20:57:44 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1AFE07) Logon Type: 3
11/20/2008 20:57:44 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1AFE07) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/20/2008 20:57:44 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1AFE07) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 22:35:44 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1C193B) Logon Type: 3
11/20/2008 22:35:44 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1C193B) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/20/2008 22:35:44 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1C193B) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/21/2008 00:30:58 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1D67DC) Logon Type: 3
11/21/2008 00:30:58 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1D67DC) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/21/2008 00:30:58 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1D67DC) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/21/2008 02:09:13 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1E86ED) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/21/2008 02:09:13 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1E86ED) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/21/2008 02:09:13 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1E86ED) Logon Type: 3
11/21/2008 03:57:27 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1FBE91) Logon Type: 3
11/21/2008 03:57:27 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1FBE91) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/21/2008 03:57:27 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1FBE91) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/21/2008 05:36:40 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x20E437) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/21/2008 05:36:40 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x20E437) Logon Type: 3
11/21/2008 05:36:40 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x20E437) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {f27bfa8a-6b3d-cf5d-05f5-3ac9a4edb07f} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/21/2008 07:21:54 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2216C4) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/21/2008 07:21:54 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2216C4) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {f27bfa8a-6b3d-cf5d-05f5-3ac9a4edb07f} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/21/2008 07:21:54 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2216C4) Logon Type: 3
11/21/2008 09:17:07 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2362C6) Logon Type: 3
11/21/2008 09:17:07 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2362C6) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/21/2008 09:17:07 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2362C6) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {f27bfa8a-6b3d-cf5d-05f5-3ac9a4edb07f} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/21/2008 10:52:21 SecurityEvent Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2475A0) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege
11/21/2008 10:52:21 SecurityEvent Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2475A0) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {f27bfa8a-6b3d-cf5d-05f5-3ac9a4edb07f} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: -
11/21/2008 10:52:21 SecurityEvent User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2475A0) Logon Type: 3
11/21/2008 11:03:13 SecurityEvent User Logoff: User Name: Administrator Domain: QMGS Logon ID: (0x0,0x24A2E8) Logon Type: 7