|
01/01/2000 01:01:01 |
|
|
009B9178,Update=009B7F78,New=009B7FC8,Status=Success,ReturnCode=0
10-06-2008 14:17:15,Update=BroadcomNetXtremeGigabit Ethernet Drivers - Microsoft Digitally Signed,New=Version 8.1B4 -[BCOM81B4-8.1B4]-,Status=Unknown,ReturnCode=1618
10-06-2008 14:17:32,Update=BroadcomNetXtremeGigabit Ethernet Drivers - Microsoft Digitally Signed,New=Version 8.1B4 -[BCOM81B4-8.1B4]-,Status=Unknown,ReturnCode=1618
009B9178,Update=009B7F78,New=009B7FC8,Status=Success,ReturnCode=0
|
|
10/06/2008 13:29:57 |
SystemEvent |
|
The NetBIOS name and DNS host name of this machine have been changed from MACHINENAME to QMGSBC-DC1. |
|
10/06/2008 13:30:15 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: MACHINENAME$ Caller Domain: Caller Logon ID: (0x0,0x3E7) Caller Process ID: 276 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 13:30:15 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/06/2008 13:30:15 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 13:30:15 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: MACHINENAME$ Caller Domain: Caller Logon ID: (0x0,0x3E7) Caller Process ID: 276 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 13:30:15 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 13:38:35 |
SystemEvent |
|
Windows Server 2003 Hotfix KB911164 was installed. |
|
10/06/2008 13:43:56 |
SystemEvent |
|
Setup successfully installed Windows build 3790. |
|
10/06/2008 13:43:57 |
SystemEvent |
|
The process winlogon.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Upgrade (Planned) Reason Code: 0x80020003 Shutdown Type: restart Comment: Windows setup has completed, and the computer must restart. |
|
10/06/2008 13:43:58 |
SystemEvent |
|
The Event log service was stopped. |
|
10/06/2008 13:43:58 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
10/06/2008 13:45:20 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/06/2008 13:45:34 |
SystemEvent |
|
The Event log service was started. |
|
10/06/2008 13:45:34 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 1 Multiprocessor Free. |
|
10/06/2008 13:45:36 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/06/2008 13:45:37 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 13:45:37 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 13:45:37 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 456 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 13:45:37 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 13:45:37 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 456 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 13:45:42 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
10/06/2008 13:45:42 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
10/06/2008 13:45:43 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB78D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 13:46:00 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10A86) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 13:46:00 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 13:46:00 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10A86) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 412 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 13:46:00 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 412 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The start type of the Distributed File System service was changed from auto start to demand start. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Computer Browser service entered the stopped state. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Windows Installer service entered the running state. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
Timeout (30000 milliseconds) waiting for a transaction response from the Dfs service. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
10/06/2008 13:47:19 |
SystemEvent |
|
The Windows Installer service was successfully sent a start control. |
|
10/06/2008 13:48:43 |
SystemEvent |
|
Windows Server 2003 R2 Hotfix R2-In-band was installed. |
|
10/06/2008 13:49:16 |
SystemEvent |
|
MMC 3.0 Hotfix MMC30Core was installed. |
|
10/06/2008 13:49:38 |
SystemEvent |
|
Windows Server 2003 R2 Hotfix R2-New-files was installed. |
|
10/06/2008 13:56:25 |
SystemEvent |
|
The Windows Installer service entered the stopped state. |
|
10/06/2008 14:12:30 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x61807) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 412 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 14:12:30 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x61807) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 14:12:30 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x61807) Logon Type: 7 |
|
10/06/2008 14:12:30 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 412 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 14:12:30 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 14:16:11 |
SystemEvent |
|
The Windows Installer service entered the running state. |
|
10/06/2008 14:16:11 |
SystemEvent |
|
The Windows Installer service was successfully sent a start control. |
|
10/06/2008 14:16:31 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 14:16:31 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Driver initialized successfully. |
|
10/06/2008 14:16:32 |
SystemEvent |
|
The Remote Access Connection Manager service was successfully sent a start control. |
|
10/06/2008 14:16:32 |
SystemEvent |
|
The Telephony service entered the running state. |
|
10/06/2008 14:16:34 |
SystemEvent |
|
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. |
|
10/06/2008 14:16:34 |
SystemEvent |
|
The Remote Access Connection Manager service entered the running state. |
|
10/06/2008 14:16:37 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Driver initialized successfully. |
|
10/06/2008 14:16:38 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Driver initialized successfully. |
|
10/06/2008 14:16:38 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 14:16:39 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time. |
|
10/06/2008 14:16:39 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 14:16:41 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time. |
|
10/06/2008 14:17:29 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Driver initialized successfully. |
|
10/06/2008 14:17:30 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 14:17:33 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Driver initialized successfully. |
|
10/06/2008 14:17:34 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 14:17:49 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10a86) |
|
10/06/2008 14:17:49 |
SystemEvent |
|
The Windows Installer service entered the stopped state. |
|
10/06/2008 14:17:49 |
SystemEvent |
|
The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: g |
|
10/06/2008 14:17:53 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
10/06/2008 14:17:53 |
SystemEvent |
|
The Event log service was stopped. |
|
10/06/2008 14:19:18 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Driver initialized successfully. |
|
10/06/2008 14:19:18 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 14:19:19 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/06/2008 14:19:19 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Driver initialized successfully. |
|
10/06/2008 14:19:20 |
SystemEvent |
|
Broadcom NetXtreme Gigab: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 14:19:30 |
SystemEvent |
|
The Event log service was started. |
|
10/06/2008 14:19:30 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 1 Multiprocessor Free. |
|
10/06/2008 14:19:31 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/06/2008 14:19:32 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 14:19:32 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 14:19:32 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 764 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 14:19:32 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 14:19:32 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 764 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 14:20:31 |
SystemEvent |
|
Your computer has automatically configured the IP address for the Network Card with network address 000D609CC160. The IP address being used is 169.254.230.196. |
|
10/06/2008 14:20:38 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
10/06/2008 14:20:38 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
10/06/2008 14:20:39 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB753) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 14:20:51 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 1 Multiprocessor Free. |
|
10/06/2008 14:20:51 |
SystemEvent |
|
The Event log service was started. |
|
10/06/2008 14:20:52 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/06/2008 14:21:13 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
10/06/2008 14:21:13 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
10/06/2008 14:21:13 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
10/06/2008 14:21:13 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
10/06/2008 14:21:13 |
SystemEvent |
|
The Computer Browser service entered the stopped state. |
|
10/06/2008 14:21:13 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
10/06/2008 14:21:13 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
10/06/2008 14:22:41 |
SecurityEvent |
|
Audit Policy Change: New Policy: Success Failure + - Logon/Logoff - - Object Access - - Privilege Use - - Account Management - - Policy Change - - System - - Detailed Tracking - - Directory Service Access + - Account Logon Changed By: User Name: MACHINENAME$ Domain Name: Logon ID: (0x0,0x3E7) |
|
10/06/2008 14:23:24 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: ROOT\DMIO\0000 Vetoing device: Root\dmio\0000 Vetoing service name: Driver\dmio Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:23:26 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: STORAGE\VOLUME\1&30A96598&0&SIGNATUREB6F0B6F0OFFSET7E00LENGTH950280000 Vetoing device: STORAGE\Volume\1&30a96598&0&SignatureB6F0B6F0Offset7E00Length950280000 Vetoing service name: FileSystem\Ntfs Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:23:28 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: ACPI\FIXEDBUTTON\2&DABA3FF&0 Vetoing device: ACPI\FixedButton\2&daba3ff&0 Vetoing service name: Driver\ACPI Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:23:49 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: PCI\VEN_1166&DEV_0203&SUBSYS_00000000&REV_B0\3&267A616A&0&78 Vetoing device: ACPI\PNP0B00\4&3a5043f3&0 Vetoing service name: Driver\ACPI Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:23:51 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: PCI\VEN_1166&DEV_0227&SUBSYS_00000000&REV_00\3&267A616A&0&7B Vetoing device: PCI\VEN_1166&DEV_0227&SUBSYS_00000000&REV_00\3&267a616a&0&7B Vetoing service name: Driver\isapnp Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:24:03 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: PCI\VEN_1166&DEV_0213&SUBSYS_02121166&REV_B0\3&267A616A&0&79 Vetoing device: IDE\DiskTOSHIBA_MK4026GAXB______________________PB104E__\5&2c80d75&0&0.0.0 Vetoing service name: Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:24:04 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: PCIIDE\IDECHANNEL\4&FA31D19&0&0 Vetoing device: IDE\DiskTOSHIBA_MK4026GAXB______________________PB104E__\5&2c80d75&0&0.0.0 Vetoing service name: Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:24:21 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: ACPI\PNP0B00\4&3A5043F3&0 Vetoing device: ACPI\PNP0B00\4&3a5043f3&0 Vetoing service name: Driver\ACPI Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:24:39 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: IDE\DISKTOSHIBA_MK4026GAXB______________________PB104E__\5&2C80D75&0&0.0.0 Vetoing device: IDE\DiskTOSHIBA_MK4026GAXB______________________PB104E__\5&2c80d75&0&0.0.0 Vetoing service name: Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/06/2008 14:25:06 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x1661D) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 14:25:06 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1661D) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 688 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 14:25:06 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 688 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 14:25:06 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 14:32:37 |
SystemEvent |
|
The Automatic Updates service was successfully sent a stop control. |
|
10/06/2008 14:32:38 |
SystemEvent |
|
The Automatic Updates service entered the stopped state. |
|
10/06/2008 14:32:44 |
SystemEvent |
|
The Automatic Updates service was successfully sent a start control. |
|
10/06/2008 14:32:45 |
SystemEvent |
|
The Automatic Updates service entered the running state. |
|
10/06/2008 14:34:37 |
SystemEvent |
|
The Computer Browser service entered the running state. |
|
10/06/2008 14:34:37 |
SystemEvent |
|
The Computer Browser service was successfully sent a start control. |
|
10/06/2008 14:37:15 |
SystemEvent |
|
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start. |
|
10/06/2008 14:37:15 |
SystemEvent |
|
The Background Intelligent Transfer Service service entered the running state. |
|
10/06/2008 14:37:15 |
SystemEvent |
|
The Background Intelligent Transfer Service service was successfully sent a start control. |
|
10/06/2008 14:37:16 |
SystemEvent |
|
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start. |
|
10/06/2008 14:37:16 |
SystemEvent |
|
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start. |
|
10/06/2008 14:37:22 |
SystemEvent |
|
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start. |
|
10/06/2008 14:37:22 |
SystemEvent |
|
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start. |
|
10/06/2008 14:37:23 |
SystemEvent |
|
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start. |
|
10/06/2008 14:38:20 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1661D) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {293015a8-9170-4d3f-4558-52e85980f3b5} Target Server Name: qmgsdc1.qmgs.internal Target Server Info: cifs/qmgsdc1.qmgs.internal Caller Process ID: 792 Source Network Address: - Source Port: - |
|
10/06/2008 14:53:17 |
SystemEvent |
|
Windows Server 2003 Service Pack 2 was installed (Service Pack 1 was previously installed). |
|
10/06/2008 14:55:23 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 688 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 14:55:23 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1101BF) Logon Type: 7 |
|
10/06/2008 14:55:23 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1101BF) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 14:55:23 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1101BF) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 688 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 14:55:23 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 14:55:37 |
SystemEvent |
|
The process winlogon.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Operating System: Service pack (Planned) Reason Code: 0x80020010 Shutdown Type: restart Comment: Windows Server 2003 Service Pack 2 |
|
10/06/2008 14:55:37 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1661d) |
|
10/06/2008 14:55:42 |
SystemEvent |
|
The Event log service was stopped. |
|
10/06/2008 14:55:42 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
10/06/2008 14:57:13 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
10/06/2008 14:57:14 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 14:57:15 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/06/2008 14:57:29 |
SystemEvent |
|
The Event log service was started. |
|
10/06/2008 14:57:29 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
10/06/2008 14:57:30 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/06/2008 14:57:32 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 14:57:32 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 14:57:32 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 14:57:32 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 14:57:32 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 14:57:46 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
10/06/2008 14:57:46 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
10/06/2008 14:57:49 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD90A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Help and Support service entered the stopped state. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Help and Support service was successfully sent a stop control. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Distributed Transaction Coordinator service entered the running state. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Distributed Transaction Coordinator service was successfully sent a start control. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Distributed Transaction Coordinator service entered the stopped state. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Distributed Transaction Coordinator service was successfully sent a stop control. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
10/06/2008 14:58:11 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
10/06/2008 14:58:12 |
SystemEvent |
|
The Help and Support service entered the running state. |
|
10/06/2008 14:58:12 |
SystemEvent |
|
The WinHTTP Web Proxy Auto-Discovery Service service was successfully sent a start control. |
|
10/06/2008 14:58:12 |
SystemEvent |
|
The WinHTTP Web Proxy Auto-Discovery Service service entered the running state. |
|
10/06/2008 14:58:12 |
SystemEvent |
|
The Help and Support service was successfully sent a start control. |
|
10/06/2008 14:58:22 |
SystemEvent |
|
The Windows Service Pack Installer update service service entered the stopped state. |
|
10/06/2008 15:01:41 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x320A4) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 15:01:41 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x320A4) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:01:41 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 15:01:41 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 15:02:39 |
SystemEvent |
|
The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: Image upload |
|
10/06/2008 15:02:40 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x320a4) |
|
10/06/2008 15:02:44 |
SystemEvent |
|
The Event log service was stopped. |
|
10/06/2008 15:02:44 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
10/06/2008 15:05:21 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
10/06/2008 15:05:22 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 15:05:25 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/06/2008 15:05:38 |
SystemEvent |
|
The Event log service was started. |
|
10/06/2008 15:05:38 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
10/06/2008 15:05:39 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/06/2008 15:05:41 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:05:41 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:05:41 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:05:41 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:05:41 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:05:49 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
10/06/2008 15:05:49 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
10/06/2008 15:05:50 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB536) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:06:40 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 15:06:40 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 15:06:40 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x122AB) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 15:06:40 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x122AB) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:06:59 |
SystemEvent |
|
The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: Image upload |
|
10/06/2008 15:06:59 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x122ab) |
|
10/06/2008 15:07:01 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x122AB) Logon Type: 2 |
|
10/06/2008 15:07:05 |
SystemEvent |
|
The Event log service was stopped. |
|
10/06/2008 15:07:05 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
10/06/2008 15:12:29 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
10/06/2008 15:12:29 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/06/2008 15:12:30 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 15:12:43 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
10/06/2008 15:12:43 |
SystemEvent |
|
The Event log service was started. |
|
10/06/2008 15:12:44 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/06/2008 15:12:46 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:12:46 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:12:46 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:12:46 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:12:46 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:12:54 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
10/06/2008 15:12:55 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
10/06/2008 15:12:56 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xCDAD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:14:18 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
10/06/2008 15:14:18 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
10/06/2008 15:14:18 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
10/06/2008 15:14:18 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
10/06/2008 15:14:18 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
10/06/2008 15:14:18 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
10/06/2008 15:27:12 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 15:27:12 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x16BEE) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:27:12 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x16BEE) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 15:27:12 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 15:27:24 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x16bee) |
|
10/06/2008 15:27:24 |
SystemEvent |
|
The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: g |
|
10/06/2008 15:27:28 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
10/06/2008 15:27:28 |
SystemEvent |
|
The Event log service was stopped. |
|
10/06/2008 15:46:17 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
10/06/2008 15:46:17 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/06/2008 15:46:18 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 15:46:29 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/06/2008 15:46:29 |
SystemEvent |
|
The Event log service was started. |
|
10/06/2008 15:46:29 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
10/06/2008 15:46:33 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:46:33 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:46:33 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:46:33 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:46:33 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:46:39 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAC47) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 15:46:39 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
10/06/2008 15:46:39 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
10/06/2008 15:47:13 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 15:47:13 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x1038D) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 15:47:13 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1038D) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 15:47:13 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 15:47:37 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1038d) |
|
10/06/2008 15:47:37 |
SystemEvent |
|
The process Explorer.EXE has initiated the shutdown of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: shutdown Comment: j |
|
10/06/2008 15:47:40 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1038D) Logon Type: 2 |
|
10/06/2008 15:47:43 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
10/06/2008 15:47:43 |
SystemEvent |
|
The Event log service was stopped. |
|
10/06/2008 16:32:00 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/06/2008 16:32:00 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
10/06/2008 16:32:01 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
10/06/2008 16:32:12 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/06/2008 16:32:12 |
SystemEvent |
|
The Event log service was started. |
|
10/06/2008 16:32:12 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
10/06/2008 16:32:16 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 16:32:16 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 16:32:16 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 16:32:16 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/06/2008 16:32:16 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 16:32:22 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
10/06/2008 16:32:22 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
10/06/2008 16:32:22 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA48F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
10/06/2008 16:33:02 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10391) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 16:33:02 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
10/06/2008 16:33:02 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
10/06/2008 16:33:02 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x10391) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
10/06/2008 16:33:17 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10391) |
|
10/06/2008 16:33:17 |
SystemEvent |
|
The process Explorer.EXE has initiated the shutdown of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: shutdown Comment: g |
|
10/06/2008 16:33:23 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10391) Logon Type: 2 |
|
10/06/2008 16:33:26 |
SystemEvent |
|
The Event log service was stopped. |
|
10/06/2008 16:33:26 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
10/07/2008 08:43:17 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
10/07/2008 08:43:18 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
10/07/2008 08:43:18 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
10/07/2008 08:43:27 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
10/07/2008 08:43:27 |
SystemEvent |
|
The Event log service was started. |
|
10/07/2008 08:43:28 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
10/07/2008 08:43:32 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: - |
|
10/07/2008 08:43:32 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/07/2008 08:43:32 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
10/07/2008 08:43:32 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: - |
|
10/07/2008 08:43:32 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
10/07/2008 08:43:41 |
SystemEvent |
|
The redirector was unable to register the address for transport NetBT_Tcpip_{691837B6-D398-4BBC-B05E for the following reason: . Transport has been taken offline. |
|
10/07/2008 08:43:41 |
SystemEvent |
|
Application popup: Windows - System Error : A duplicate name exists on the network. |
|
10/07/2008 08:43:41 |
SystemEvent |
|
The name "QMGSBC-DC1 :0" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.4 did not allow the name to be claimed by this machine. |
|
10/07/2008 08:43:42 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA0A1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
10/07/2008 08:43:42 |
SystemEvent |
|
The name "QMGSBC-DC1 :20" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.4 did not allow the name to be claimed by this machine. |
|
10/07/2008 08:43:42 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
10/07/2008 08:43:42 |
SystemEvent |
|
The server could not bind to the transport \Device\NetBT_Tcpip_{691837B6-D398-4BBC-B05E-62F1E1527CD8} because another computer on the network has the same name. The server could not start. |
|
10/07/2008 08:43:42 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
10/07/2008 08:44:15 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: IDE\DISKTOSHIBA_MK4019GAXB______________________FB002B__\34384A3437393331205420202020202020202020 Vetoing device: IDE\DiskTOSHIBA_MK4019GAXB______________________FB002B__\34384a3437393331205420202020202020202020 Vetoing service name: Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/07/2008 08:44:17 |
SystemEvent |
|
The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below. Vetoed device: STORAGE\VOLUME\1&30A96598&0&SIGNATUREB6F0B6F0OFFSET7E00LENGTH950A58200 Vetoing device: STORAGE\Volume\1&30a96598&0&SignatureB6F0B6F0Offset7E00Length950A58200 Vetoing service name: FileSystem\Ntfs Veto type 6: PNP_VetoDevice When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation. User Action Restart your computer. |
|
10/07/2008 08:45:10 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
10/07/2008 08:45:10 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
10/07/2008 08:45:10 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
10/07/2008 08:45:10 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
10/07/2008 08:45:10 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
10/07/2008 08:45:10 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
10/07/2008 09:43:10 |
SystemEvent |
|
The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent. |
|
10/07/2008 12:00:00 |
SystemEvent |
|
The system uptime is 11811 seconds. |
|
10/08/2008 08:43:42 |
SystemEvent |
|
The time service has not synchronized the system time for 86400 seconds because none of the time service providers provided a usable time stamp. The time service is no longer synchronized and cannot provide the time to other clients or update the system clock. Monitor the system events displayed in the Event Viewer to make sure that a more serious problem does not exist. |
|
11/14/2008 15:27:53 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
11/14/2008 15:27:53 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
11/14/2008 15:27:53 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
11/14/2008 15:27:56 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: The network link is down. Check to make sure the network cable is properly connected. |
|
11/14/2008 15:28:03 |
SystemEvent |
|
The system detected that network adapter Broadcom NetXtreme Gigabit Ethernet #2 was disconnected from the network, and the adapter's network configuration has been released. If the network adapter was not disconnected, this may indicate that it has malfunctioned. Please contact your vendor for updated drivers. |
|
11/14/2008 15:28:03 |
SystemEvent |
|
The previous system shutdown at 15:42:27 on 09/10/2008 was unexpected. |
|
11/14/2008 15:28:03 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
11/14/2008 15:28:03 |
SystemEvent |
|
The Event log service was started. |
|
11/14/2008 15:28:04 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
11/14/2008 15:28:06 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
11/14/2008 15:28:06 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
11/14/2008 15:28:07 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: - |
|
11/14/2008 15:28:07 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
11/14/2008 15:28:07 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x9407) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/14/2008 15:28:07 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/14/2008 15:28:07 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: - |
|
11/14/2008 15:28:07 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/14/2008 15:28:08 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
11/14/2008 15:28:13 |
SystemEvent |
|
The system detected that network adapter Broadcom NetXtreme Gigabit Ethernet #2 was connected to the network, and has initiated normal operation over the network adapter. |
|
11/14/2008 15:29:16 |
SystemEvent |
|
Your computer has automatically configured the IP address for the Network Card with network address 000D609CD33D. The IP address being used is 169.254.68.89. |
|
11/14/2008 15:29:16 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. |
|
11/14/2008 15:29:16 |
SystemEvent |
|
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) |
|
11/14/2008 15:29:18 |
SystemEvent |
|
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) |
|
11/14/2008 15:29:18 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. |
|
11/14/2008 15:29:20 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. |
|
11/14/2008 15:29:20 |
SystemEvent |
|
Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) |
|
11/14/2008 15:29:22 |
SystemEvent |
|
The server could not bind to the transport \Device\NetBT_Tcpip_{691837B6-D398-4BBC-B05E-62F1E1527CD8} because another computer on the network has the same name. The server could not start. |
|
11/14/2008 15:29:22 |
SystemEvent |
|
The name "QMGSBC-DC1 :20" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.6 did not allow the name to be claimed by this machine. |
|
11/14/2008 15:29:25 |
SystemEvent |
|
The name "QMGSBC-DC1 :0" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.6 did not allow the name to be claimed by this machine. |
|
11/14/2008 15:29:25 |
SystemEvent |
|
The redirector was unable to register the address for transport NetBT_Tcpip_{691837B6-D398-4BBC-B05E for the following reason: . Transport has been taken offline. |
|
11/14/2008 15:29:25 |
SystemEvent |
|
The name "QMGSBC-DC1 :20" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.2.6 did not allow the name to be claimed by this machine. |
|
11/14/2008 15:29:25 |
SystemEvent |
|
The server could not bind to the transport \Device\NetBT_Tcpip_{691837B6-D398-4BBC-B05E-62F1E1527CD8} because another computer on the network has the same name. The server could not start. |
|
11/14/2008 15:29:25 |
SystemEvent |
|
Application popup: Windows - System Error : A duplicate name exists on the network. |
|
11/14/2008 15:29:51 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
11/14/2008 15:29:51 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
11/14/2008 15:29:51 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
11/14/2008 15:29:51 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
11/14/2008 15:29:51 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
11/14/2008 15:29:51 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
11/14/2008 16:27:45 |
SystemEvent |
|
The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent. |
|
11/14/2008 21:58:16 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x30478) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/14/2008 21:58:24 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x30478) Logon Type: 3 |
|
11/15/2008 04:58:19 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x317F8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/15/2008 04:58:29 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x317F8) Logon Type: 3 |
|
11/15/2008 11:58:17 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x32964) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/15/2008 11:58:25 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x32964) Logon Type: 3 |
|
11/15/2008 12:00:00 |
SystemEvent |
|
The system uptime is 73936 seconds. |
|
11/15/2008 15:28:06 |
SystemEvent |
|
The time service has not synchronized the system time for 86400 seconds because none of the time service providers provided a usable time stamp. The time service is no longer synchronized and cannot provide the time to other clients or update the system clock. Monitor the system events displayed in the Event Viewer to make sure that a more serious problem does not exist. |
|
11/15/2008 18:58:20 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x38B2A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/15/2008 18:58:32 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x38B2A) Logon Type: 3 |
|
11/16/2008 01:58:19 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x39B3E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/16/2008 01:58:28 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x39B3E) Logon Type: 3 |
|
11/16/2008 08:58:22 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x3ACA5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/16/2008 08:58:31 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x3ACA5) Logon Type: 3 |
|
11/16/2008 12:00:00 |
SystemEvent |
|
The system uptime is 160336 seconds. |
|
11/16/2008 15:58:23 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x40EC8) Logon Type: 3 |
|
11/16/2008 15:58:23 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x40EC8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/16/2008 22:58:25 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x42208) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/16/2008 22:58:31 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x42208) Logon Type: 3 |
|
11/17/2008 05:58:26 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x433F1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 05:58:35 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x433F1) Logon Type: 3 |
|
11/17/2008 09:08:11 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/17/2008 09:08:11 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 344 Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 09:08:11 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x4478D) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 344 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 09:08:11 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x4478D) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/17/2008 09:08:13 |
SystemEvent |
|
The reason supplied by user QMGSBC-DC1\Administrator for the last unexpected shutdown of this computer is: Other (Unplanned) Reason Code: 0xa000000 Bug ID: Bugcheck String: Comment: g |
|
11/17/2008 09:08:25 |
SystemEvent |
|
The process Explorer.EXE has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Other (Planned) Reason Code: 0x85000000 Shutdown Type: restart Comment: d |
|
11/17/2008 09:08:26 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x4478d) |
|
11/17/2008 09:08:27 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x4478D) Logon Type: 2 |
|
11/17/2008 09:08:30 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
11/17/2008 09:08:30 |
SystemEvent |
|
The Event log service was stopped. |
|
11/17/2008 13:50:45 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
11/17/2008 13:50:46 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
11/17/2008 13:50:46 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
11/17/2008 13:50:56 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
11/17/2008 13:50:56 |
SystemEvent |
|
The Event log service was started. |
|
11/17/2008 13:50:56 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
11/17/2008 13:51:01 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 13:51:01 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 392 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 13:51:01 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/17/2008 13:51:01 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/17/2008 13:51:01 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 13:51:07 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA6B1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 13:51:07 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
11/17/2008 13:51:07 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
11/17/2008 13:53:52 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
11/17/2008 13:53:53 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
11/17/2008 13:53:53 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
11/17/2008 13:54:06 |
SystemEvent |
|
The previous system shutdown at 13:50:56 on 17/11/2008 was unexpected. |
|
11/17/2008 13:54:06 |
SystemEvent |
|
The Event log service was started. |
|
11/17/2008 13:54:06 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
11/17/2008 13:54:07 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
11/17/2008 13:54:11 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 13:54:11 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/17/2008 13:54:11 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 13:54:11 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 13:54:11 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/17/2008 13:54:16 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAC5F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 13:54:16 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
11/17/2008 13:54:16 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
11/17/2008 13:55:45 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
11/17/2008 13:55:45 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
11/17/2008 13:55:45 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
11/17/2008 13:55:45 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
11/17/2008 13:55:45 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
11/17/2008 13:55:45 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
11/17/2008 13:56:48 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x15F0B) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/17/2008 13:56:48 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x15F0B) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 13:56:48 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 13:56:48 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/17/2008 13:56:50 |
SystemEvent |
|
The reason supplied by user QMGSBC-DC1\Administrator for the last unexpected shutdown of this computer is: Other (Unplanned) Reason Code: 0xa000000 Bug ID: d Bugcheck String: Comment: d |
|
11/17/2008 14:12:10 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x220CE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 14:12:13 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x220CE) Logon Type: 3 |
|
11/17/2008 14:53:45 |
SystemEvent |
|
The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent. |
|
11/17/2008 14:56:51 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x25A4F) Logon Type: 7 |
|
11/17/2008 14:56:51 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x25A4F) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/17/2008 14:56:51 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x25A4F) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 14:56:51 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 14:56:51 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/17/2008 14:58:49 |
SystemEvent |
|
Windows Server 2003 Hotfix KB925336 was installed. |
|
11/17/2008 15:01:09 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x15f0b) |
|
11/17/2008 15:01:09 |
SystemEvent |
|
The process winlogon.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: Operating System: Hot fix (Planned) Reason Code: 0x80020011 Shutdown Type: restart Comment: Hotfix for Windows Server 2003 (KB925336) |
|
11/17/2008 15:01:14 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
11/17/2008 15:01:14 |
SystemEvent |
|
The Event log service was stopped. |
|
11/17/2008 15:02:39 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
11/17/2008 15:02:40 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
11/17/2008 15:02:40 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
11/17/2008 15:02:55 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
11/17/2008 15:02:55 |
SystemEvent |
|
The Event log service was started. |
|
11/17/2008 15:02:55 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
11/17/2008 15:03:00 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:03:00 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/17/2008 15:03:00 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:03:00 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/17/2008 15:03:00 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:03:05 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
11/17/2008 15:03:06 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAF93) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:03:06 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
11/17/2008 15:03:51 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/17/2008 15:03:51 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10416) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 15:03:51 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x10416) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/17/2008 15:03:51 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 15:04:34 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
11/17/2008 15:04:34 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
11/17/2008 15:04:34 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
11/17/2008 15:04:34 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
11/17/2008 15:04:34 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
11/17/2008 15:04:34 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
11/17/2008 15:09:07 |
SystemEvent |
|
The Windows Installer service was successfully sent a start control. |
|
11/17/2008 15:09:07 |
SystemEvent |
|
The Windows Installer service entered the running state. |
|
11/17/2008 15:11:52 |
SystemEvent |
|
The start type of the VMware Server Web Access service was changed from demand start to auto start. |
|
11/17/2008 15:11:53 |
SystemEvent |
|
The VMware Server Web Access service was successfully sent a start control. |
|
11/17/2008 15:11:55 |
SystemEvent |
|
The VMware Server Web Access service entered the running state. |
|
11/17/2008 15:13:30 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x5FEDD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 15:13:31 |
SystemEvent |
|
The VMware Bridge Protocol service was successfully sent a start control. |
|
11/17/2008 15:13:35 |
SystemEvent |
|
The description for Event ID ( 00001 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: |
|
11/17/2008 15:13:35 |
SystemEvent |
|
The description for Event ID ( 00004 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: \Device\VMnetUserif0 |
|
11/17/2008 15:13:36 |
SystemEvent |
|
The VMware NAT Service service entered the running state. |
|
11/17/2008 15:13:36 |
SystemEvent |
|
The VMware NAT Service service was successfully sent a start control. |
|
11/17/2008 15:13:37 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x5FEDD) Logon Type: 3 |
|
11/17/2008 15:13:40 |
SystemEvent |
|
The VMware DHCP Service service was successfully sent a start control. |
|
11/17/2008 15:13:40 |
SystemEvent |
|
The VMware DHCP Service service entered the running state. |
|
11/17/2008 15:13:46 |
SystemEvent |
|
The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Starting up: 0x8957faf0, \REGISTRY\MACHINE\SYSTEM\Contr |
|
11/17/2008 15:13:46 |
SystemEvent |
|
The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Driver entry successful. |
|
11/17/2008 15:13:47 |
SystemEvent |
|
The Remote Access Connection Manager service was successfully sent a start control. |
|
11/17/2008 15:13:47 |
SystemEvent |
|
The Telephony service entered the running state. |
|
11/17/2008 15:13:48 |
SystemEvent |
|
The Remote Access Connection Manager service entered the running state. |
|
11/17/2008 15:13:49 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time. |
|
11/17/2008 15:13:49 |
SystemEvent |
|
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. |
|
11/17/2008 15:13:49 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time. |
|
11/17/2008 15:13:58 |
SystemEvent |
|
The server could not bind to the transport \Device\NetBT_Tcpip_{29C4D1CD-1997-4A46-969F-AE522B22DAFE}. |
|
11/17/2008 15:14:09 |
SystemEvent |
|
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. |
|
11/17/2008 15:14:10 |
SystemEvent |
|
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. |
|
11/17/2008 15:14:13 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time. |
|
11/17/2008 15:14:15 |
SystemEvent |
|
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 1 minutes. NtpClient has no source of accurate time. |
|
11/17/2008 15:14:24 |
SystemEvent |
|
The VMware vmx86 service was successfully sent a start control. |
|
11/17/2008 15:14:25 |
SystemEvent |
|
The VMware hcmon service was successfully sent a start control. |
|
11/17/2008 15:14:30 |
SecurityEvent |
|
Successful Logon: User Name: __vmware_user__ Domain: QMGSBC-DC1 Logon ID: (0x0,0x74EE2) Logon Type: 2 Logon Process: Advapi Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 2704 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:14:30 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: __vmware_user__ Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/17/2008 15:14:30 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: __vmware_user__ Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 2704 Source Network Address: - Source Port: - |
|
11/17/2008 15:14:31 |
SystemEvent |
|
The VMware Authorization Service service entered the running state. |
|
11/17/2008 15:14:31 |
SystemEvent |
|
The VMware Authorization Service service was successfully sent a start control. |
|
11/17/2008 15:14:32 |
SystemEvent |
|
The VMware vmci service was successfully sent a start control. |
|
11/17/2008 15:14:54 |
SystemEvent |
|
The VMware Host Agent service was successfully sent a start control. |
|
11/17/2008 15:14:54 |
SystemEvent |
|
The VMware Host Agent service entered the running state. |
|
11/17/2008 15:15:20 |
SystemEvent |
|
The process msiexec.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found Reason Code: 0x80030002 Shutdown Type: restart Comment: The Windows Installer initiated a system restart to complete or continue the configuration of 'VMware Server'. |
|
11/17/2008 15:15:21 |
SystemEvent |
|
The Windows Installer service entered the stopped state. |
|
11/17/2008 15:15:21 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x10416) |
|
11/17/2008 15:15:31 |
SystemEvent |
|
The Event log service was stopped. |
|
11/17/2008 15:15:31 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
11/17/2008 15:17:02 |
SystemEvent |
|
The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Starting up: 0x899f3720, \REGISTRY\MACHINE\SYSTEM\Contr |
|
11/17/2008 15:17:02 |
SystemEvent |
|
The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Driver entry successful. |
|
11/17/2008 15:17:03 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
11/17/2008 15:17:03 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
11/17/2008 15:17:04 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
11/17/2008 15:17:18 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
11/17/2008 15:17:18 |
SystemEvent |
|
The Event log service was started. |
|
11/17/2008 15:17:18 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
11/17/2008 15:17:23 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:17:23 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/17/2008 15:17:23 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:17:23 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/17/2008 15:17:23 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 396 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:17:32 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
11/17/2008 15:17:32 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
11/17/2008 15:17:33 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB981) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:17:42 |
SystemEvent |
|
The description for Event ID ( 00001 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: |
|
11/17/2008 15:17:42 |
SystemEvent |
|
The description for Event ID ( 00004 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: \Device\VMnetUserif0 |
|
11/17/2008 15:17:46 |
SecurityEvent |
|
Successful Logon: User Name: __vmware_user__ Domain: QMGSBC-DC1 Logon ID: (0x0,0xFFFF) Logon Type: 2 Logon Process: Advapi Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 1472 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:17:46 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: __vmware_user__ Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 1472 Source Network Address: - Source Port: - |
|
11/17/2008 15:17:46 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: __vmware_user__ Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/17/2008 15:18:35 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 15:18:35 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/17/2008 15:18:35 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/17/2008 15:18:35 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/17/2008 15:18:53 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
11/17/2008 15:18:53 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
11/17/2008 15:18:53 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
11/17/2008 15:18:53 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
11/17/2008 15:18:53 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
11/17/2008 15:18:53 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
11/17/2008 15:23:37 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 1528 Source Network Address: - Source Port: - |
|
11/17/2008 15:23:37 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/17/2008 15:23:37 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x35B7F) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/17/2008 15:23:37 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x35B7F) Logon Type: 2 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 1528 Transited Services: - Source Network Address: - Source Port: - |
|
11/17/2008 15:25:24 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x3B7CA) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 15:25:24 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x3B7CA) Logon Type: 3 |
|
11/17/2008 15:34:27 |
SystemEvent |
|
The Windows Installer service entered the running state. |
|
11/17/2008 15:34:27 |
SystemEvent |
|
The Windows Installer service was successfully sent a start control. |
|
11/17/2008 15:40:37 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x59134) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 15:40:42 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x59134) Logon Type: 3 |
|
11/17/2008 15:55:55 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x6E7FB) Logon Type: 3 |
|
11/17/2008 15:55:55 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x6E7FB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 15:58:07 |
SystemEvent |
|
The Windows Installer service entered the stopped state. |
|
11/17/2008 15:59:35 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x35B7F) Logon Type: 2 |
|
11/17/2008 16:04:22 |
SystemEvent |
|
The master browser has received a server announcement from the computer PC2-2 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{691837B6-D398-4BBC-B05. The master browser is stopping or an election is being forced. |
|
11/17/2008 16:12:01 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x71C26) Logon Type: 3 |
|
11/17/2008 16:12:01 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x71C26) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 16:16:53 |
SystemEvent |
|
The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent. |
|
11/17/2008 16:18:15 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x72FE8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 16:18:22 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x72FE8) Logon Type: 3 |
|
11/17/2008 16:25:21 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x7970E) Logon Type: 3 |
|
11/17/2008 16:25:21 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x7970E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 16:40:24 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x7C027) Logon Type: 3 |
|
11/17/2008 16:40:24 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x7C027) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 16:55:37 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x7EC3F) Logon Type: 3 |
|
11/17/2008 16:55:37 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x7EC3F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 17:10:38 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x815FC) Logon Type: 3 |
|
11/17/2008 17:10:38 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x815FC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 17:21:15 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x8330C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 17:21:23 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x8330C) Logon Type: 3 |
|
11/17/2008 17:25:25 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x83E9C) Logon Type: 3 |
|
11/17/2008 17:25:25 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x83E9C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 17:40:24 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x867C0) Logon Type: 3 |
|
11/17/2008 17:40:24 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x867C0) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 17:55:37 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x890EF) Logon Type: 3 |
|
11/17/2008 17:55:37 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x890EF) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 18:10:43 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x8BA33) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 18:10:44 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x8BA33) Logon Type: 3 |
|
11/17/2008 18:21:32 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x8D77E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 18:21:35 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x8D77E) Logon Type: 3 |
|
11/17/2008 18:25:25 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x8E3CB) Logon Type: 3 |
|
11/17/2008 18:25:25 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x8E3CB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 18:40:26 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x90C88) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 18:40:26 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x90C88) Logon Type: 3 |
|
11/17/2008 18:55:53 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x936B3) Logon Type: 3 |
|
11/17/2008 18:55:53 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x936B3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 19:10:27 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x95E49) Logon Type: 3 |
|
11/17/2008 19:10:27 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x95E49) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 19:22:00 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x97D8D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 19:22:09 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x97D8D) Logon Type: 3 |
|
11/17/2008 19:25:28 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x98733) Logon Type: 3 |
|
11/17/2008 19:25:28 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x98733) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 19:40:28 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x9AFD5) Logon Type: 3 |
|
11/17/2008 19:40:28 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x9AFD5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 19:55:52 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x9D985) Logon Type: 3 |
|
11/17/2008 19:55:52 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x9D985) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 19:58:31 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x9E0AB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 19:58:34 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x9E0AB) Logon Type: 3 |
|
11/17/2008 20:10:29 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA0131) Logon Type: 3 |
|
11/17/2008 20:10:29 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA0131) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 20:22:19 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA22F8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 20:22:30 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA22F8) Logon Type: 3 |
|
11/17/2008 20:25:29 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA2BB9) Logon Type: 3 |
|
11/17/2008 20:25:29 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA2BB9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 20:40:30 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA54AB) Logon Type: 3 |
|
11/17/2008 20:40:30 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA54AB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 20:55:52 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xA7E65) Logon Type: 3 |
|
11/17/2008 20:55:52 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA7E65) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 21:10:38 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xAA647) Logon Type: 3 |
|
11/17/2008 21:10:38 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAA647) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 21:22:11 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAC826) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 21:22:15 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xAC826) Logon Type: 3 |
|
11/17/2008 21:25:31 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xAD158) Logon Type: 3 |
|
11/17/2008 21:25:31 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAD158) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 21:40:32 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xAF9E8) Logon Type: 3 |
|
11/17/2008 21:40:32 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xAF9E8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 21:55:57 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB2569) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 21:55:57 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB2569) Logon Type: 3 |
|
11/17/2008 22:10:33 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB4D60) Logon Type: 3 |
|
11/17/2008 22:10:33 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB4D60) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 22:21:38 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB6B77) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 22:21:43 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB6B77) Logon Type: 3 |
|
11/17/2008 22:25:33 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB761C) Logon Type: 3 |
|
11/17/2008 22:25:33 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB761C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 22:40:33 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB9EAC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 22:40:33 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xB9EAC) Logon Type: 3 |
|
11/17/2008 22:55:57 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xBC866) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 22:55:57 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xBC866) Logon Type: 3 |
|
11/17/2008 23:10:46 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xBF087) Logon Type: 3 |
|
11/17/2008 23:10:46 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xBF087) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 23:21:57 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC0EDB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 23:22:08 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC0EDB) Logon Type: 3 |
|
11/17/2008 23:25:35 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC18B8) Logon Type: 3 |
|
11/17/2008 23:25:35 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC18B8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 23:40:36 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC432E) Logon Type: 3 |
|
11/17/2008 23:40:36 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC432E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/17/2008 23:55:59 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC6D47) Logon Type: 3 |
|
11/17/2008 23:55:59 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC6D47) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 00:10:44 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xC95BA) Logon Type: 3 |
|
11/18/2008 00:10:44 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xC95BA) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 00:22:06 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xCB493) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 00:22:16 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xCB493) Logon Type: 3 |
|
11/18/2008 00:25:38 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xCBE21) Logon Type: 3 |
|
11/18/2008 00:25:38 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xCBE21) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 00:40:38 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xCE6BA) Logon Type: 3 |
|
11/18/2008 00:40:38 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xCE6BA) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 00:56:01 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD10A5) Logon Type: 3 |
|
11/18/2008 00:56:01 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD10A5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 01:10:44 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD3A20) Logon Type: 3 |
|
11/18/2008 01:10:44 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD3A20) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 01:21:57 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD58D1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 01:22:02 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD58D1) Logon Type: 3 |
|
11/18/2008 01:25:40 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD62E6) Logon Type: 3 |
|
11/18/2008 01:25:40 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD62E6) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 01:40:40 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xD8B80) Logon Type: 3 |
|
11/18/2008 01:40:40 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xD8B80) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 01:56:06 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xDB587) Logon Type: 3 |
|
11/18/2008 01:56:06 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xDB587) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 02:10:48 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xDDD59) Logon Type: 3 |
|
11/18/2008 02:10:48 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xDDD59) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 02:22:06 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xDFC05) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 02:22:10 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xDFC05) Logon Type: 3 |
|
11/18/2008 02:25:42 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE05E5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 02:25:42 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE05E5) Logon Type: 3 |
|
11/18/2008 02:40:42 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE2E7E) Logon Type: 3 |
|
11/18/2008 02:40:42 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE2E7E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 02:56:02 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE5810) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 02:56:02 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE5810) Logon Type: 3 |
|
11/18/2008 02:58:31 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE5EA4) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 02:58:35 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE5EA4) Logon Type: 3 |
|
11/18/2008 03:10:42 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xE820B) Logon Type: 3 |
|
11/18/2008 03:10:42 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xE820B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 03:22:11 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xEA3B7) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 03:22:13 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xEA3B7) Logon Type: 3 |
|
11/18/2008 03:25:43 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xEAD7F) Logon Type: 3 |
|
11/18/2008 03:25:43 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xEAD7F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 03:40:43 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xED61B) Logon Type: 3 |
|
11/18/2008 03:40:43 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xED61B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 03:56:13 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xEFFFE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 03:56:13 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xEFFFE) Logon Type: 3 |
|
11/18/2008 04:10:55 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xF27B4) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 04:10:55 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xF27B4) Logon Type: 3 |
|
11/18/2008 04:21:50 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xF4573) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 04:21:59 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xF4573) Logon Type: 3 |
|
11/18/2008 04:25:44 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xF501D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 04:25:44 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xF501D) Logon Type: 3 |
|
11/18/2008 04:40:45 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xF7B1E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 04:40:45 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xF7B1E) Logon Type: 3 |
|
11/18/2008 04:56:07 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xFA537) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 04:56:07 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xFA537) Logon Type: 3 |
|
11/18/2008 05:10:46 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xFCCE5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 05:10:46 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xFCCE5) Logon Type: 3 |
|
11/18/2008 05:22:15 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xFEBE3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 05:22:16 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xFEBE3) Logon Type: 3 |
|
11/18/2008 05:25:47 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0xFF5A9) Logon Type: 3 |
|
11/18/2008 05:25:47 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xFF5A9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 05:40:47 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x101E41) Logon Type: 3 |
|
11/18/2008 05:40:47 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x101E41) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 05:56:08 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1047F3) Logon Type: 3 |
|
11/18/2008 05:56:08 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1047F3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 06:10:53 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x106FBD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 06:10:53 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x106FBD) Logon Type: 3 |
|
11/18/2008 06:21:54 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x108DC5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 06:21:56 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x108DC5) Logon Type: 3 |
|
11/18/2008 06:25:49 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x109AFD) Logon Type: 3 |
|
11/18/2008 06:25:49 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x109AFD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 06:40:50 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x10C3C6) Logon Type: 3 |
|
11/18/2008 06:40:50 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x10C3C6) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 06:56:19 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x10EE6B) Logon Type: 3 |
|
11/18/2008 06:56:19 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x10EE6B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 07:11:06 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1116C7) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 07:11:06 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1116C7) Logon Type: 3 |
|
11/18/2008 07:21:05 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x113204) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 07:21:14 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x113204) Logon Type: 3 |
|
11/18/2008 07:25:54 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x113F21) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 07:25:54 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x113F21) Logon Type: 3 |
|
11/18/2008 07:40:55 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1167E4) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 07:40:55 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1167E4) Logon Type: 3 |
|
11/18/2008 07:56:25 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x119241) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 07:56:25 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x119241) Logon Type: 3 |
|
11/18/2008 08:11:01 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x11BBB2) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 08:11:01 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x11BBB2) Logon Type: 3 |
|
11/18/2008 08:20:01 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x11D432) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 08:20:05 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x11D432) Logon Type: 3 |
|
11/18/2008 08:25:57 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x11E426) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 08:25:57 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x11E426) Logon Type: 3 |
|
11/18/2008 08:40:55 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x120D20) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 08:40:55 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x120D20) Logon Type: 3 |
|
11/18/2008 08:56:16 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1236FE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 08:56:16 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1236FE) Logon Type: 3 |
|
11/18/2008 09:11:00 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x125F01) Logon Type: 3 |
|
11/18/2008 09:11:00 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x125F01) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 09:14:03 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x126799) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 09:14:05 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x126799) Logon Type: 3 |
|
11/18/2008 09:25:56 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x128A68) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 09:25:56 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x128A68) Logon Type: 3 |
|
11/18/2008 09:40:57 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x12B37C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 09:40:57 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x12B37C) Logon Type: 3 |
|
11/18/2008 09:56:05 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x12DED1) Logon Type: 3 |
|
11/18/2008 09:56:05 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x12DED1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 09:58:10 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x12E499) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 09:58:14 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x12E499) Logon Type: 3 |
|
11/18/2008 10:10:59 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x130794) Logon Type: 3 |
|
11/18/2008 10:10:59 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x130794) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 10:13:24 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x130E55) Logon Type: 3 |
|
11/18/2008 10:13:24 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x130E55) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 10:25:59 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x133094) Logon Type: 3 |
|
11/18/2008 10:25:59 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x133094) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 10:41:00 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1359E1) Logon Type: 3 |
|
11/18/2008 10:41:00 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1359E1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 10:56:10 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x13834A) Logon Type: 3 |
|
11/18/2008 10:56:10 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x13834A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 11:11:01 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x13ABC3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 11:11:01 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x13ABC3) Logon Type: 3 |
|
11/18/2008 11:13:47 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x13B358) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 11:13:48 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x13B358) Logon Type: 3 |
|
11/18/2008 11:26:34 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x13D603) Logon Type: 3 |
|
11/18/2008 11:26:34 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x13D603) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 11:41:34 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x14009C) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 11:41:34 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x14009C) Logon Type: 3 |
|
11/18/2008 11:56:22 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1428F5) Logon Type: 3 |
|
11/18/2008 11:56:22 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1428F5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 12:00:00 |
SystemEvent |
|
The system uptime is 74588 seconds. |
|
11/18/2008 12:09:58 |
SystemEvent |
|
The master browser has received a server announcement from the computer PC2-2 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{691837B6-D398-4BBC-B05. The master browser is stopping or an election is being forced. |
|
11/18/2008 12:13:26 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x14572D) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 12:13:27 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x14572D) Logon Type: 3 |
|
11/18/2008 13:14:21 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x14FC7B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 13:14:30 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x14FC7B) Logon Type: 3 |
|
11/18/2008 14:14:20 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x15A020) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 14:14:26 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x15A020) Logon Type: 3 |
|
11/18/2008 14:26:09 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x15C122) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 14:26:09 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x15C122) Logon Type: 3 |
|
11/18/2008 14:41:12 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x15E9E9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 14:41:12 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x15E9E9) Logon Type: 3 |
|
11/18/2008 14:56:46 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x16148E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 14:56:46 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x16148E) Logon Type: 3 |
|
11/18/2008 15:11:13 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x163D93) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 15:11:13 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x163D93) Logon Type: 3 |
|
11/18/2008 15:15:11 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x16484B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 15:15:16 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x16484B) Logon Type: 3 |
|
11/18/2008 15:17:42 |
SystemEvent |
|
The time service has not synchronized the system time for 86400 seconds because none of the time service providers provided a usable time stamp. The time service is no longer synchronized and cannot provide the time to other clients or update the system clock. Monitor the system events displayed in the Event Viewer to make sure that a more serious problem does not exist. |
|
11/18/2008 15:26:11 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x166BB9) Logon Type: 3 |
|
11/18/2008 15:26:11 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x166BB9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 15:41:11 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x169470) Logon Type: 3 |
|
11/18/2008 15:41:11 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x169470) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 15:52:48 |
SystemEvent |
|
The master browser has received a server announcement from the computer PC2-2 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{691837B6-D398-4BBC-B05. The master browser is stopping or an election is being forced. |
|
11/18/2008 16:18:22 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x16F9BF) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 16:18:34 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x16F9BF) Logon Type: 3 |
|
11/18/2008 16:58:26 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x17AF1F) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 16:58:30 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x17AF1F) Logon Type: 3 |
|
11/18/2008 17:22:23 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x17F1B7) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 17:22:32 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x17F1B7) Logon Type: 3 |
|
11/18/2008 17:38:42 |
SystemEvent |
|
The name "WORKGROUP :1d" could not be registered on the Interface with IP address 192.168.5.1. The machine with the IP address 192.168.5.165 did not allow the name to be claimed by this machine. |
|
11/18/2008 17:49:01 |
SystemEvent |
|
The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is unknown. |
|
11/18/2008 18:22:26 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1894F6) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 18:22:31 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1894F6) Logon Type: 3 |
|
11/18/2008 18:41:47 |
SystemEvent |
|
The browser was unable to promote itself to master browser. The browser will continue to attempt to promote itself to the master browser, but will no longer log any events in the event log in Event Viewer. |
|
11/18/2008 19:23:08 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x193B02) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 19:23:12 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x193B02) Logon Type: 3 |
|
11/18/2008 20:23:46 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x19DF99) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 20:23:50 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x19DF99) Logon Type: 3 |
|
11/18/2008 21:23:33 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1A85A5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 21:23:36 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1A85A5) Logon Type: 3 |
|
11/18/2008 22:24:07 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1B2BCC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 22:24:11 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1B2BCC) Logon Type: 3 |
|
11/18/2008 23:24:07 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1BCE23) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 23:24:10 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1BCE23) Logon Type: 3 |
|
11/18/2008 23:58:30 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1C2BA3) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/18/2008 23:58:32 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1C2BA3) Logon Type: 3 |
|
11/19/2008 00:24:14 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1C7368) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 00:24:17 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1C7368) Logon Type: 3 |
|
11/19/2008 01:23:34 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1D13FE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 01:23:36 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1D13FE) Logon Type: 3 |
|
11/19/2008 02:23:25 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1DB847) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 02:23:30 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1DB847) Logon Type: 3 |
|
11/19/2008 03:23:59 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1E5EA0) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 03:24:01 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1E5EA0) Logon Type: 3 |
|
11/19/2008 04:23:45 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1F02A1) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 04:23:57 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1F02A1) Logon Type: 3 |
|
11/19/2008 05:23:18 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x1FA3FB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 05:23:24 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x1FA3FB) Logon Type: 3 |
|
11/19/2008 06:23:56 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x2049D5) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 06:24:00 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x2049D5) Logon Type: 3 |
|
11/19/2008 06:58:31 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x20A79B) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 06:58:33 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x20A79B) Logon Type: 3 |
|
11/19/2008 07:21:47 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x20E8DD) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 07:21:51 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x20E8DD) Logon Type: 3 |
|
11/19/2008 08:17:08 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x217EAC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 08:17:13 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x217EAC) Logon Type: 3 |
|
11/19/2008 09:13:03 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x221860) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 09:13:10 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x221860) Logon Type: 3 |
|
11/19/2008 10:13:24 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x22BE59) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 10:13:33 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x22BE59) Logon Type: 3 |
|
11/19/2008 10:56:45 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/19/2008 10:56:46 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/19/2008 10:56:46 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x2343B1) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/19/2008 10:56:46 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x2343B1) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 10:56:46 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x2343B1) Logon Type: 7 |
|
11/19/2008 10:56:54 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/19/2008 10:56:54 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 1528 Source Network Address: - Source Port: - |
|
11/19/2008 10:56:54 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x23461D) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 10:56:54 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x23461D) Logon Type: 2 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 1528 Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 11:13:09 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x24B4BC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 11:13:18 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x24B4BC) Logon Type: 3 |
|
11/19/2008 11:29:51 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x260F89) Logon Type: 7 |
|
11/19/2008 11:29:51 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x260F89) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 11:29:51 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x260F89) Logon Type: 7 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-DC1 Logon GUID: - Caller User Name: QMGSBC-DC1$ Caller Domain: WORKGROUP Caller Logon ID: (0x0,0x3E7) Caller Process ID: 348 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/19/2008 11:29:51 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGSBC-DC1 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 348 Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/19/2008 11:29:51 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: Administrator Source Workstation: QMGSBC-DC1 Error Code: 0x0 |
|
11/19/2008 11:31:10 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {6d13d746-7791-45fb-be8a-ffb1b539be0d} Target Server Name: QMGSDC1 Target Server Info: cifs/QMGSDC1 Caller Process ID: 408 Source Network Address: - Source Port: - |
|
11/19/2008 11:31:26 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {fbb88fc6-5a45-ddef-9d4e-eaaad627f0fd} Target Server Name: QMGSDC1 Target Server Info: cifs/QMGSDC1 Caller Process ID: 408 Source Network Address: - Source Port: - |
|
11/19/2008 11:31:30 |
SystemEvent |
|
The Net Logon service entered the running state. |
|
11/19/2008 11:31:30 |
SystemEvent |
|
The start type of the Net Logon service was changed from demand start to auto start. |
|
11/19/2008 11:31:30 |
SystemEvent |
|
The Net Logon service was successfully sent a start control. |
|
11/19/2008 11:31:31 |
SystemEvent |
|
This computer has been successfully joined to domain 'qmgs'. |
|
11/19/2008 11:31:51 |
SystemEvent |
|
Attempt to update DNS Host Name of the computer object in Active Directory failed. The updated value was 'qmgsbc-dc1'. The following error occurred: The parameter is incorrect. |
|
11/19/2008 11:31:51 |
SystemEvent |
|
Attempt to update HOST Service Principal Names (SPNs) of the computer object in Active Directory failed. The updated values were 'HOST/qmgsbc-dc1' and 'HOST/QMGSBC-DC1'. The following error occurred: The parameter is incorrect. |
|
11/19/2008 11:32:00 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1B915) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {b9907fa1-8773-d424-9d81-423b76d9fb1f} Target Server Name: QMGSDC1 Target Server Info: cifs/QMGSDC1 Caller Process ID: 408 Source Network Address: - Source Port: - |
|
11/19/2008 11:32:00 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {b9907fa1-8773-d424-9d81-423b76d9fb1f} Target Server Name: QMGSDC1.qmgs.internal Target Server Info: ldap/QMGSDC1.qmgs.internal Caller Process ID: 408 Source Network Address: - Source Port: - |
|
11/19/2008 11:32:01 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-DC1$ Domain: WORKGROUP Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: administrator Target Domain: QMGS.INTERNAL Target Logon GUID: {b9907fa1-8773-d424-9d81-423b76d9fb1f} Target Server Name: QMGSDC1 Target Server Info: LDAP/QMGSDC1 Caller Process ID: 408 Source Network Address: - Source Port: - |
|
11/19/2008 11:32:23 |
SystemEvent |
|
The process rundll32.exe has initiated the restart of computer QMGSBC-DC1 on behalf of user QMGSBC-DC1\Administrator for the following reason: No title for this reason could be found Reason Code: 0x80050004 Shutdown Type: restart Comment: |
|
11/19/2008 11:32:23 |
SecurityEvent |
|
User initiated logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x1b915) |
|
11/19/2008 11:32:33 |
SystemEvent |
|
The VMware Host Agent service entered the stopped state. |
|
11/19/2008 11:32:36 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGSBC-DC1 Logon ID: (0x0,0x23461D) Logon Type: 2 |
|
11/19/2008 11:32:47 |
SecurityEvent |
|
Windows is shutting down. All logon sessions will be terminated by this shutdown. |
|
11/19/2008 11:32:47 |
SystemEvent |
|
The Event log service was stopped. |
|
11/19/2008 11:34:20 |
SystemEvent |
|
The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Driver entry successful. |
|
11/19/2008 11:34:20 |
SystemEvent |
|
The description for Event ID ( 00034 ) in Source ( VMnetAdapter ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: Starting up: 0x89ba7030, \REGISTRY\MACHINE\SYSTEM\Contr |
|
11/19/2008 11:34:21 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Driver initialized successfully. |
|
11/19/2008 11:34:22 |
SystemEvent |
|
Broadcom NetXtreme Gigabit Ethernet #2: Network controller configured for 1Gb full-duplex link. |
|
11/19/2008 11:34:22 |
SystemEvent |
|
The IPSec Driver is starting in Bypass mode. No IPSec security is being applied while this computer starts up. IPSec policies, if they have been assigned, will be applied to this computer after the IPSec services start. |
|
11/19/2008 11:34:39 |
SystemEvent |
|
The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog. |
|
11/19/2008 11:34:39 |
SystemEvent |
|
The Event log service was started. |
|
11/19/2008 11:34:39 |
SystemEvent |
|
Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Multiprocessor Free. |
|
11/19/2008 11:34:39 |
SystemEvent |
|
The NetBIOS name and DNS host name of this machine have been changed from QMGSBC-DC1 to QMGSBC-VM2. |
|
11/19/2008 11:34:43 |
SecurityEvent |
|
Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-VM2$ Caller Domain: QMGS Caller Logon ID: (0x0,0x3E7) Caller Process ID: 400 Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 11:34:43 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/19/2008 11:34:43 |
SecurityEvent |
|
Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: - Caller User Name: QMGSBC-VM2$ Caller Domain: QMGS Caller Logon ID: (0x0,0x3E7) Caller Process ID: 400 Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 11:34:43 |
SecurityEvent |
|
Successful Logon: User Name: SYSTEM Domain: NT AUTHORITY Logon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - Authentication Package: - Workstation Name: - Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: 4 Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 11:34:43 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges: SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege |
|
11/19/2008 11:34:53 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xB3D4) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 11:34:53 |
SystemEvent |
|
The Application Experience Lookup service started successfully. |
|
11/19/2008 11:34:53 |
SystemEvent |
|
The IPSec driver has entered Secure mode. IPSec policies, if they have been configured, are now being applied to this computer. |
|
11/19/2008 11:34:53 |
SystemEvent |
|
The description for Event ID ( 00001 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: |
|
11/19/2008 11:34:53 |
SystemEvent |
|
The description for Event ID ( 00004 ) in Source ( VMnetuserif ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages. The following information is part of the event: \Device\VMnetUserif0 |
|
11/19/2008 11:35:09 |
SecurityEvent |
|
Successful Logon: User Name: __vmware_user__ Domain: QMGSBC-VM2 Logon ID: (0x0,0xCC4E) Logon Type: 2 Logon Process: Advapi Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Workstation Name: QMGSBC-VM2 Logon GUID: - Caller User Name: QMGSBC-VM2$ Caller Domain: QMGS Caller Logon ID: (0x0,0x3E7) Caller Process ID: 1440 Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 11:35:09 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: __vmware_user__ Target Domain: QMGSBC-VM2 Target Logon GUID: - Target Server Name: localhost Target Server Info: localhost Caller Process ID: 1440 Source Network Address: - Source Port: - |
|
11/19/2008 11:35:09 |
SecurityEvent |
|
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: __vmware_user__ Source Workstation: QMGSBC-VM2 Error Code: 0x0 |
|
11/19/2008 11:35:09 |
SystemEvent |
|
The time provider NtpClient is currently receiving valid time data from qmgsdc1.QMGS.internal (ntp.d|192.168.5.1:123->192.168.0.1:123). |
|
11/19/2008 12:30:21 |
SystemEvent |
|
The time service is now synchronizing the system time with the time source qmgsdc1.QMGS.internal (ntp.d|192.168.5.1:123->192.168.0.1:123). |
|
11/19/2008 12:31:11 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: Domain: Logon ID: (0x0,0x1C2AF) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 12:31:11 |
SecurityEvent |
|
Successful Logon: User Name: Administrator Domain: QMGS Logon ID: (0x0,0x1C2AF) Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: QMGSBC-VM2 Logon GUID: {212b45e1-0314-0767-6733-ac03a8198538} Caller User Name: QMGSBC-VM2$ Caller Domain: QMGS Caller Logon ID: (0x0,0x3E7) Caller Process ID: 352 Transited Services: - Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/19/2008 12:31:11 |
SecurityEvent |
|
Logon attempt using explicit credentials: Logged on user: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x3E7) Logon GUID: - User whose credentials were used: Target User Name: Administrator Target Domain: QMGS Target Logon GUID: {212b45e1-0314-0767-6733-ac03a8198538} Target Server Name: localhost Target Server Info: localhost Caller Process ID: 352 Source Network Address: 127.0.0.1 Source Port: 0 |
|
11/19/2008 12:31:13 |
SystemEvent |
|
The Network Location Awareness (NLA) service was successfully sent a start control. |
|
11/19/2008 12:31:13 |
SystemEvent |
|
The Network Location Awareness (NLA) service entered the running state. |
|
11/19/2008 12:31:13 |
SystemEvent |
|
The Terminal Services service entered the running state. |
|
11/19/2008 12:31:13 |
SystemEvent |
|
The Application Layer Gateway Service service was successfully sent a start control. |
|
11/19/2008 12:31:13 |
SystemEvent |
|
The Application Layer Gateway Service service entered the running state. |
|
11/19/2008 12:31:13 |
SystemEvent |
|
The Terminal Services service was successfully sent a start control. |
|
11/19/2008 12:31:15 |
SystemEvent |
|
The Telephony service entered the running state. |
|
11/19/2008 12:31:15 |
SystemEvent |
|
The Remote Access Connection Manager service was successfully sent a start control. |
|
11/19/2008 12:31:15 |
SystemEvent |
|
The Remote Access Connection Manager service entered the running state. |
|
11/19/2008 12:31:35 |
SystemEvent |
|
The Windows Installer service was successfully sent a start control. |
|
11/19/2008 12:31:35 |
SystemEvent |
|
The Windows Installer service entered the running state. |
|
11/19/2008 12:32:26 |
SystemEvent |
|
The WinHTTP Web Proxy Auto-Discovery Service service was successfully sent a start control. |
|
11/19/2008 12:32:26 |
SystemEvent |
|
The WinHTTP Web Proxy Auto-Discovery Service service entered the running state. |
|
11/19/2008 12:41:36 |
SystemEvent |
|
The Windows Installer service entered the stopped state. |
|
11/19/2008 12:48:56 |
SystemEvent |
|
The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down. |
|
11/19/2008 12:48:56 |
SystemEvent |
|
The WinHTTP Web Proxy Auto-Discovery Service service entered the stopped state. |
|
11/19/2008 12:48:56 |
SystemEvent |
|
The WinHTTP Web Proxy Auto-Discovery Service suspended operation. |
|
11/19/2008 12:55:03 |
SystemEvent |
|
The system uptime is 1551 seconds. |
|
11/19/2008 13:08:33 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x490D8) Logon Type: 3 |
|
11/19/2008 13:08:33 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x490D8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:08:33 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x490C7) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:08:33 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x490C7) Logon Type: 3 |
|
11/19/2008 13:09:56 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSAV1$ Domain: QMGS Logon ID: (0x0,0x49492) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {6778f910-c28e-b6b2-a16d-924523e72afc} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:10:08 |
SecurityEvent |
|
User Logoff: User Name: QMGSAV1$ Domain: QMGS Logon ID: (0x0,0x49492) Logon Type: 3 |
|
11/19/2008 13:21:47 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4B6AC) Logon Type: 3 |
|
11/19/2008 13:21:47 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4B6AC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:21:48 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4B6D9) Logon Type: 3 |
|
11/19/2008 13:21:48 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4B6D9) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:21:52 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4B6EC) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:21:52 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4B6F8) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:21:52 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4B6F8) Logon Type: 3 |
|
11/19/2008 13:21:52 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4B6EC) Logon Type: 3 |
|
11/19/2008 13:29:13 |
SystemEvent |
|
The driver has detected that device \Device\Harddisk0\DR0 has predicted that it will fail. Immediately back up your data and replace your hard disk drive. A failure may be imminent. |
|
11/19/2008 13:36:47 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4E15A) Logon Type: 3 |
|
11/19/2008 13:36:47 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4E15A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:36:48 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4E187) Logon Type: 3 |
|
11/19/2008 13:36:48 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4E187) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:36:53 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4E1B2) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:36:53 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4E1B2) Logon Type: 3 |
|
11/19/2008 13:36:53 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x4E1BE) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:36:53 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x4E1BE) Logon Type: 3 |
|
11/19/2008 13:51:48 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x50C27) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:51:48 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x50C27) Logon Type: 3 |
|
11/19/2008 13:51:49 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x50C36) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:51:49 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x50C36) Logon Type: 3 |
|
11/19/2008 13:52:10 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x50D2A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:52:10 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x50D2A) Logon Type: 3 |
|
11/19/2008 13:52:10 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x50D36) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 13:52:10 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x50D36) Logon Type: 3 |
|
11/19/2008 14:06:48 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x536D0) Logon Type: 3 |
|
11/19/2008 14:06:48 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x536D0) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 14:06:49 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x536DF) Logon Type: 3 |
|
11/19/2008 14:06:49 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x536DF) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 14:07:21 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x538A0) Logon Type: 3 |
|
11/19/2008 14:07:21 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x538A0) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 14:07:21 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x53892) Logon Type: 3 |
|
11/19/2008 14:07:21 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x53892) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 14:10:47 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSAV1$ Domain: QMGS Logon ID: (0x0,0x5442E) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {6778f910-c28e-b6b2-a16d-924523e72afc} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 14:10:48 |
SecurityEvent |
|
User Logoff: User Name: QMGSAV1$ Domain: QMGS Logon ID: (0x0,0x5442E) Logon Type: 3 |
|
11/19/2008 14:21:49 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x563FB) Logon Type: 3 |
|
11/19/2008 14:21:49 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x563FB) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 14:21:50 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x5640A) Logon Type: 3 |
|
11/19/2008 14:21:50 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x5640A) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 14:21:54 |
SecurityEvent |
|
Successful Network Logon: User Name: Domain: Logon ID: (0x0,0x5644E) Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: QMGSAV1 Logon GUID: - Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.5.239 Source Port: 0 |
|
11/19/2008 14:21:54 |
SecurityEvent |
|
User Logoff: User Name: ANONYMOUS LOGON Domain: NT AUTHORITY Logon ID: (0x0,0x5644E) Logon Type: 3 |
|
11/19/2008 14:23:16 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x568A3) Logon Type: 3 |
|
11/19/2008 14:23:16 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x568A3) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 14:23:16 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x568A3) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 16:06:33 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x6B82B) Logon Type: 3 |
|
11/19/2008 16:06:33 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x6B82B) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 16:06:33 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x6B82B) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 17:40:33 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x81405) Logon Type: 3 |
|
11/19/2008 17:40:33 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x81405) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 17:40:33 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x81405) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 19:31:33 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x95588) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 19:31:33 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x95588) Logon Type: 3 |
|
11/19/2008 19:31:33 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x95588) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 21:09:33 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xA7588) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/19/2008 21:09:33 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xA7588) Logon Type: 3 |
|
11/19/2008 21:09:33 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xA7588) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {1e042bc3-748b-a6de-ce9a-d2124bbe6db4} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 22:49:47 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xB97A1) Logon Type: 3 |
|
11/19/2008 22:49:47 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xB97A1) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/19/2008 22:49:47 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xB97A1) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 00:21:53 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xCA2AB) Logon Type: 3 |
|
11/20/2008 00:21:53 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xCA2AB) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 00:21:53 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xCA2AB) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 02:15:07 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xDE907) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 02:15:07 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xDE907) Logon Type: 3 |
|
11/20/2008 02:15:07 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xDE907) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 03:48:21 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xEF678) Logon Type: 3 |
|
11/20/2008 03:48:21 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xEF678) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 03:48:21 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0xEF678) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 05:32:21 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x102A1C) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 05:32:21 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x102A1C) Logon Type: 3 |
|
11/20/2008 05:32:21 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x102A1C) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 07:03:34 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1132D6) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {df8bb303-7772-2ab0-bc5b-9c3e6f158f60} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 07:03:34 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1132D6) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 07:03:35 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1132D6) Logon Type: 3 |
|
11/20/2008 08:34:49 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x123FB6) Logon Type: 3 |
|
11/20/2008 08:34:49 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x123FB6) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 08:34:49 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x123FB6) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 10:31:03 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x138E01) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 10:31:03 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x138E01) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 10:31:03 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x138E01) Logon Type: 3 |
|
11/20/2008 12:00:00 |
SystemEvent |
|
The system uptime is 84648 seconds. |
|
11/20/2008 12:07:17 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x14A373) Logon Type: 3 |
|
11/20/2008 12:07:17 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x14A373) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 12:07:17 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x14A373) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 13:53:30 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x15E20E) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 13:53:30 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x15E20E) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 13:53:31 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x15E20E) Logon Type: 3 |
|
11/20/2008 15:49:30 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1731DB) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 15:49:30 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1731DB) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 15:49:30 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1731DB) Logon Type: 3 |
|
11/20/2008 17:32:44 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x185BF7) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 17:32:44 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x185BF7) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {4cc2df0e-523c-ab20-b907-d7a5f1a9d545} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 17:32:44 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x185BF7) Logon Type: 3 |
|
11/20/2008 19:06:44 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x19B7CD) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 19:06:44 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x19B7CD) Logon Type: 3 |
|
11/20/2008 19:06:44 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x19B7CD) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 20:57:44 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1AFE07) Logon Type: 3 |
|
11/20/2008 20:57:44 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1AFE07) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/20/2008 20:57:44 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1AFE07) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 22:35:44 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1C193B) Logon Type: 3 |
|
11/20/2008 22:35:44 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1C193B) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/20/2008 22:35:44 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1C193B) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/21/2008 00:30:58 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1D67DC) Logon Type: 3 |
|
11/21/2008 00:30:58 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1D67DC) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/21/2008 00:30:58 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1D67DC) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/21/2008 02:09:13 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1E86ED) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/21/2008 02:09:13 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1E86ED) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/21/2008 02:09:13 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1E86ED) Logon Type: 3 |
|
11/21/2008 03:57:27 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1FBE91) Logon Type: 3 |
|
11/21/2008 03:57:27 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1FBE91) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {dbd40c8d-52f6-838e-4c3e-6c9ca49fcc68} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/21/2008 03:57:27 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x1FBE91) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/21/2008 05:36:40 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x20E437) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/21/2008 05:36:40 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x20E437) Logon Type: 3 |
|
11/21/2008 05:36:40 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x20E437) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {f27bfa8a-6b3d-cf5d-05f5-3ac9a4edb07f} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/21/2008 07:21:54 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2216C4) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/21/2008 07:21:54 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2216C4) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {f27bfa8a-6b3d-cf5d-05f5-3ac9a4edb07f} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/21/2008 07:21:54 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2216C4) Logon Type: 3 |
|
11/21/2008 09:17:07 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2362C6) Logon Type: 3 |
|
11/21/2008 09:17:07 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2362C6) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/21/2008 09:17:07 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2362C6) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {f27bfa8a-6b3d-cf5d-05f5-3ac9a4edb07f} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/21/2008 10:52:21 |
SecurityEvent |
|
Special privileges assigned to new logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2475A0) Privileges: SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege |
|
11/21/2008 10:52:21 |
SecurityEvent |
|
Successful Network Logon: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2475A0) Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: Logon GUID: {f27bfa8a-6b3d-cf5d-05f5-3ac9a4edb07f} Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: - Source Port: - |
|
11/21/2008 10:52:21 |
SecurityEvent |
|
User Logoff: User Name: QMGSBC-VM2$ Domain: QMGS Logon ID: (0x0,0x2475A0) Logon Type: 3 |
|
11/21/2008 11:03:13 |
SecurityEvent |
|
User Logoff: User Name: Administrator Domain: QMGS Logon ID: (0x0,0x24A2E8) Logon Type: 7 |